ืคื’ื™ืขื•ืช ื‘- Apache Tomcat ื”ืžืืคืฉืจืช ื”ื—ืœืคืช ืงื•ื“ JSP ื•ืงื‘ืœืช ืงื‘ืฆื™ ืืคืœื™ืงืฆื™ื•ืช ืื™ื ื˜ืจื ื˜

ื—ื•ืงืจื™ื ืžื”ื—ื‘ืจื” ื”ืกื™ื ื™ืช Chaitin Tech ื–ื™ื”ื• ืคื’ื™ืขื•ืช (CVE-2020-1938) ื‘ ืืคืืฆ 'ื™ ื˜ื•ืžืื˜, ืžื™ืžื•ืฉ ืงื•ื“ ืคืชื•ื— ืฉืœ Java Servlet, JavaServer Pages, Java Expression Language ื•ื˜ื›ื ื•ืœื•ื’ื™ื•ืช Java WebSocket. ื”ืคื’ื™ืขื•ืช ืงื™ื‘ืœื” ืืช ืฉื ื”ืงื•ื“ Ghostcat ื•ืจืžืช ื—ื•ืžืจื” ืงืจื™ื˜ื™ืช (9.8 CVSS). ื”ื‘ืขื™ื” ืžืืคืฉืจืช, ื‘ืชืฆื•ืจืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ, ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉื” ืœื™ืฆื™ืืช ืจืฉืช 8009, ืœืงืจื•ื ืืช ื”ืชื•ื›ืŸ ืฉืœ ื›ืœ ืงื‘ืฆื™ื ืžืกืคืจื™ื™ืช ื™ื™ืฉื•ืžื™ ื”ืื™ื ื˜ืจื ื˜, ื›ื•ืœืœ ืงื‘ืฆื™ื ืขื ื”ื’ื“ืจื•ืช ื•ืงื•ื“ื™ ืžืงื•ืจ ืฉืœ ื™ื™ืฉื•ืžื™ื.

ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ื’ื ืœื™ื™ื‘ื ืงื‘ืฆื™ื ืื—ืจื™ื ืœืงื•ื“ ื”ืืคืœื™ืงืฆื™ื”, ืžื” ืฉืžืืคืฉืจ ืœืืจื’ืŸ ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืฉืจืช ืื ื”ืืคืœื™ืงืฆื™ื” ืžืืคืฉืจืช ื”ืขืœืืช ืงื‘ืฆื™ื ืœืฉืจืช (ืœื“ื•ื’ืžื”, ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืขืœื•ืช ืกืงืจื™ืคื˜ JSP ื‘ืžืกื•ื•ื” ืฉืœ ืชืžื•ื ื” ื“ืจืš ื˜ื•ืคืก ื”ืขืœืืช ื”ืชืžื•ื ื”). ื ื™ืชืŸ ืœื‘ืฆืข ื”ืชืงืคื” ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉื” ืœื™ืฆื™ืืช ืจืฉืช ืขื ืžื˜ืคืœ AJP. ืœืคื™ ื ืชื•ื ื™ื ืจืืฉื•ื ื™ื™ื, ื‘ืื™ื ื˜ืจื ื˜ ืžืฆืืชื™ ื™ื•ืชืจ ืž-1.2 ืžื™ืœื™ื•ืŸ ืžืืจื—ื™ื ืฉืžืงื‘ืœื™ื ื‘ืงืฉื•ืช ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ AJP.

ื”ืคื’ื™ืขื•ืช ืงื™ื™ืžืช ื‘ืคืจื•ื˜ื•ืงื•ืœ AJP, ื• ืœื ื ืงืจื ืฉื’ื™ืืช ื™ื™ืฉื•ื. ื‘ื ื•ืกืฃ ืœืงื‘ืœืช ื—ื™ื‘ื•ืจื™ื ื‘ืืžืฆืขื•ืช HTTP (ื™ืฆื™ืื” 8080), Apache Tomcat ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืžืืคืฉืจืช ื’ื™ืฉื” ืœื™ื™ืฉื•ื ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ AJP (ืคืจื•ื˜ื•ืงื•ืœ Apache JServ, ื™ืฆื™ืื” 8009), ืฉื”ื™ื ืžืงื‘ื™ืœื” ื‘ื™ื ืืจื™ืช ืžื•ืชืืžืช ืœื‘ื™ืฆื•ืขื™ื ืฉืœ HTTP, ื”ืžืฉืžืฉืช ื‘ื“ืจืš ื›ืœืœ ื‘ืขืช ื™ืฆื™ืจืช ืืฉื›ื•ืœ ืฉืœ ืฉืจืชื™ Tomcat ืื• ื›ื“ื™ ืœื”ืื™ืฅ ืืช ื”ืชืงืฉื•ืจืช ืขื Tomcat ื‘ืคืจื•ืงืกื™ ื”ืคื•ืš ืื• ืžืื–ืŸ ืขื•ืžืกื™ื.

AJP ืžืกืคืงืช ืคื•ื ืงืฆื™ื” ืกื˜ื ื“ืจื˜ื™ืช ืœื’ื™ืฉื” ืœืงื‘ืฆื™ื ื‘ืฉืจืช, ื‘ื” ื ื™ืชืŸ ืœื”ืฉืชืžืฉ, ืœืจื‘ื•ืช ื”ืฉื’ืช ืงื‘ืฆื™ื ืฉืื™ื ื ื ืชื•ื ื™ื ืœื—ืฉื™ืคื”. AJP ืืžื•ืจื” ืœื”ื™ื•ืช ื ื’ื™ืฉื” ืจืง ืœืฉืจืชื™ื ืžื”ื™ืžื ื™ื, ืืš ืœืžืขืฉื” ืชืฆื•ืจืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ Tomcat ื”ื™ื™ืชื” ืœื”ืคืขื™ืœ ืืช ื”ืžื˜ืคืœ ื‘ื›ืœ ืžืžืฉืงื™ ื”ืจืฉืช ื•ืœืงื‘ืœ ื‘ืงืฉื•ืช ืœืœื ืื™ืžื•ืช. ื’ื™ืฉื” ืืคืฉืจื™ืช ืœื›ืœ ืงื‘ืฆื™ ื™ื™ืฉื•ื ืื™ื ื˜ืจื ื˜, ื›ื•ืœืœ ื”ืชื•ื›ืŸ ืฉืœ WEB-INF, META-INF ื•ื›ืœ ืกืคืจื™ื™ื” ืื—ืจืช ืฉื ื™ืชื ื” ื‘ืืžืฆืขื•ืช ื”ืงืจื™ืื” ServletContext.getResourceAsStream() . AJP ื’ื ืžืืคืฉืจ ืœืš ืœื”ืฉืชืžืฉ ื‘ื›ืœ ืงื•ื‘ืฅ ื‘ืกืคืจื™ื•ืช ื”ื ื’ื™ืฉื•ืช ืฉืœ ื™ื™ืฉื•ื ื”ืื™ื ื˜ืจื ื˜ ื›ืกืงืจื™ืคื˜ JSP.

ื”ื‘ืขื™ื” ื‘ืื” ืœื™ื“ื™ ื‘ื™ื˜ื•ื™ ืžืื– ื”ืขื ืฃ ืฉืœ Tomcat 13.x ืฉื™ืฆื ืœืคื ื™ 6 ืฉื ื™ื. ื—ื•ืฅ ืžื‘ืขื™ื™ืช Tomcat ื™ืฉื™ืจื•ืช ืžืฉืคื™ืข ื•ืžื•ืฆืจื™ื ื”ืžืฉืชืžืฉื™ื ื‘ื•, ื›ื’ื•ืŸ Red Hat JBoss Web Server (JWS), JBoss Enterprise Application Platform (EAP), ื•ื›ืŸ ื™ื™ืฉื•ืžื™ ืื™ื ื˜ืจื ื˜ ืขืฆืžืื™ื™ื ื”ืžืฉืชืžืฉื™ื ืžื’ืฃ ืื‘ื™ื‘. ืคื’ื™ืขื•ืช ื“ื•ืžื” (CVE-2020-1745) ื”ื•ื•ื” ื‘ืฉืจืช ื”ืื™ื ื˜ืจื ื˜ ื–ึถืจึถื ืชึทื—ืชึดื™ื‘ืฉื™ืžื•ืฉ ื‘ืฉืจืช ื”ื™ื™ืฉื•ืžื™ื Wildfly. ื‘-JBoss ื•ื‘-Wildfly, ืคืจื•ื˜ื•ืงื•ืœ AJP ืžื•ืคืขืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืจืง ื‘ืคืจื•ืคื™ืœื™ื standalone-full-ha.xml, ืขืฆืžืื™-ha.xml ื•-ha/full-ha ื‘-domain.xml. ื‘-Spring Boot, ืชืžื™ื›ืช AJP ืžื•ืฉื‘ืชืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ. ื™ื•ืชืจ ืžืชืจื™ืกืจ ื“ื•ื’ืžืื•ืช ืขื‘ื•ื“ื” ืฉืœ ืžืขืœืœื™ื ื”ื•ื›ื ื• ืขืœ ื™ื“ื™ ืงื‘ื•ืฆื•ืช ืฉื•ื ื•ืช (
1,
2,
3,
4,
5,
6,
7,
8,
9,
10,
11).

ืคื’ื™ืขื•ืช ืชื•ืงื ื” ื‘ืžื”ื“ื•ืจื•ืช ืฉืœ Tomcat 9.0.31, 8.5.51 ะธ 7.0.100 (ืขื ืฃ ืชื—ื–ื•ืงื” 6.x ื”ื•ืคืกืง). ืืชื” ื™ื›ื•ืœ ืœืขืงื•ื‘ ืื—ืจ ื”ื•ืคืขืช ื”ืขื“ื›ื•ื ื™ื ื‘ื”ืคืฆื•ืช ื‘ื“ืคื™ื ืืœื”: ื“ื‘ื™ืืŸ, ืื•ื‘ื•ื ื˜ื•, ืจื”ืœ, ืคื“ื•ืจื”, SUSE, FreeBSD. ื›ื“ืจืš ืœืขืงื™ืคืช ื”ื‘ืขื™ื”, ืืชื” ื™ื›ื•ืœ ืœื”ืฉื‘ื™ืช ืืช ืฉื™ืจื•ืช Tomcat AJP Connector (ืœืื’ื“ ืืช ืฉืงืข ื”ื”ืื–ื ื” ืœ-localhost ืื• ืœื”ืขื™ืจ ืืช ื”ืงื• ืขื ื™ืฆื™ืืช Connector = "8009") ืื ืื™ืŸ ืฆื•ืจืš, ืื• ืœื”ื’ื“ื™ืจ ื’ื™ืฉื” ืžืื•ืžืชืช ื‘ืืžืฆืขื•ืช ื”ืžืืคื™ื™ื ื™ื "ืกื•ื“ื™" ื•"ื›ืชื•ื‘ืช", ืื ื”ืฉื™ืจื•ืช ืžืฉืžืฉ ืœืื™ื ื˜ืจืืงืฆื™ื” ืขื ืฉืจืชื™ื ื•ืคืจื•ืงืกื™ ืื—ืจื™ื ื”ืžื‘ื•ืกืกื™ื ืขืœ mod_jk ื•-mod_proxy_ajp (mod_cluster ืื™ื ื• ืชื•ืžืš ื‘ืื™ืžื•ืช).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”