ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ Apache Tomcat ื•ื•ืึธืก ืึทืœืึทื•ื– ืกืึทื‘ืกื˜ื™ื˜ื•ืฉืึทืŸ ืคื•ืŸ JSP ืงืึธื“ ืื•ืŸ ื‘ืึทืงื•ืžืขืŸ ื•ื•ืขื‘ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ื˜ืขืงืขืก

ืจืขืกืขืึทืจื˜ืฉืขืจืก ืคื•ืŸ ื“ื™ ื›ื™ื ืขื–ื™ืฉ ืคื™ืจืžืข Chaitin Tech ื”ืึธื‘ืŸ ื“ื™ืกืงืึทื•ื•ืขืจื“ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2020-1938) ืื™ืŸ ืึทืคึผืึทื˜ืฉื™ ื˜ืึธืžืงืึทื˜, ืึทืŸ ืึธืคึฟืŸ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ Java Servlet, JavaServer Pages, Java Expression Language ืื•ืŸ Java WebSocket ื˜ืขืงื ืึทืœืึทื“ื–ืฉื™ื–. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืึทืกื™ื™ื ื“ ื“ื™ ืงืึธื“ ื ืึธืžืขืŸ Ghostcat ืื•ืŸ ืึท ืงืจื™ื˜ื™ืฉ ืฉื˜ืจืขื ื’ืงื™ื™ึทื˜ ืžื“ืจื’ื” (9.8 CVSS). ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืึทืœืึทื•ื–, ืื™ืŸ ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ, ื“ื•ืจืš ืฉื™ืงืŸ ืึท ื‘ืงืฉื” ืื•ื™ืฃ ื ืขืฅ ืคึผืึธืจื˜ 8009, ืฆื• ืœื™ื™ืขื ืขืŸ ื“ื™ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ ืงื™ื™ืŸ ื˜ืขืงืขืก ืคึฟื•ืŸ ื“ื™ ื•ื•ืขื‘ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ื˜ืขืงืขืก ืžื™ื˜ ืกืขื˜ื˜ื™ื ื’ืก ืื•ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืžืงื•ืจ ืงืึธื•ื“ื–.

ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื•ื™ืš ืžืื›ื˜ ืขืก ืžืขื’ืœืขืš ืฆื• ืึทืจื™ื™ึทื ืคื™ืจ ืื ื“ืขืจืข ื˜ืขืงืขืก ืื™ืŸ ื“ื™ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืงืึธื“, ื•ื•ืึธืก ืึทืœืึทื•ื– ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืื•ื™ืฃ ื“ื™ ืกืขืจื•ื•ืขืจ ืื•ื™ื‘ ื“ื™ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืึทืœืึทื•ื– ื˜ืขืงืขืก ืฆื• ื–ื™ื™ืŸ ื•ืคึผืœืึธืึทื“ืขื“ ืฆื• ื“ื™ ืกืขืจื•ื•ืขืจ (ืœืžืฉืœ, ืึท ืึทื˜ืึทืงืขืจ ืงืขื ืขืŸ ืฆื•ืคึฟืขืœื™ืงืขืจ ืึท JSP ืฉืจื™ืคื˜ ื“ื™ืกื’ื™ื™ื–ื“ ื•ื•ื™ ืึท ื‘ื™ืœื“ ื“ื•ืจืš ื“ื™ ื‘ื™ืœื“ ื•ืคึผืœืึธืึทื“ ืคืึธืจืขื). ื“ื™ ื‘ืึทืคืึทืœืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ื•ื•ืขืŸ ืขืก ืื™ื– ืžืขื’ืœืขืš ืฆื• ืฉื™ืงืŸ ืึท ื‘ืงืฉื” ืฆื• ืึท ื ืขืฅ ืคึผืึธืจื˜ ืžื™ื˜ ืึท AJP ื”ืึทื ื“ืœืขืจ. ืœื•ื™ื˜ ืคึผืจื™ืœื™ืžืึทื ืขืจื™ ื“ืึทื˜ืŸ, ืึธื ืœื™ื™ืŸ ื’ืขืคื•ื ืขืŸ ืžืขืจ ื•ื•ื™ 1.2 ืžื™ืœื™ืึธืŸ ืžื—ื ื•ืช ืึธื ื ืขืžืขืŸ ืจื™ืงื•ื•ืขืก ื“ื•ืจืš ื“ื™ AJP ืคึผืจืึธื˜ืึธืงืึธืœ.

ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ื™ื’ื–ื™ืกืฅ ืื™ืŸ ื“ื™ AJP ืคึผืจืึธื˜ืึธืงืึธืœ, ืื•ืŸ ื ื™ืฉื˜ ื’ืขืจื•ืคืŸ ื˜ืขื•ืช ืื™ืŸ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ. ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืฆื• ืึธื ื ืขืžืขืŸ ืงืึทื ืขืงืฉืึทื ื– ื“ื•ืจืš ื”ื˜ื˜ืคึผ (ืคึผืึธืจื˜ 8080), Apache Tomcat ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜ ืึทืœืึทื•ื– ืึทืงืกืขืก ืฆื• ืึท ื•ื•ืขื‘ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ื“ื•ืจืš ื“ื™ AJP ืคึผืจืึธื˜ืึธืงืึธืœ (ืึทืคึผืึทื˜ืฉื™ ื“ื–ืฉืกืขืจื•ื• ืคึผืจืึธื˜ืึธืงืึธืœ, ืคึผืึธืจื˜ 8009), ื•ื•ืึธืก ืื™ื– ืึท ื‘ื™ื™ื ืขืจื™ ืึทื ืึทืœืึธื’ ืคื•ืŸ ื”ื˜ื˜ืคึผ ืึธืคึผื˜ื™ืžื™ื–ืขื“ ืคึฟืึทืจ ื”ืขื›ืขืจ ืคืึธืจืฉื˜ืขืœื•ื ื’, ื™ื•ื–ืฉืึทื•ื•ืึทืœื™ ื’ืขื ื™ืฆื˜ ื•ื•ืขืŸ ืงืจื™ื™ื™ื˜ื™ื ื’ ืึท ืงื ื•ื™ืœ ืคื•ืŸ Tomcat ืกืขืจื•ื•ืขืจืก ืึธื“ืขืจ ืฆื• ืคืึทืจื’ื™ื›ืขืจืŸ ื™ื ื˜ืขืจืึทืงืฉืึทืŸ ืžื™ื˜ Tomcat ืื•ื™ืฃ ืึท ืคืึทืจืงืขืจื˜ ืคึผืจืึทืงืกื™ ืึธื“ืขืจ ืžืึทืกืข ื‘ืึทืœืึทื ืกืขืจ.

AJP ื’ื™ื˜ ืึท ื ืึธืจืžืึทืœ ืคื•ื ืงืฆื™ืข ืคึฟืึทืจ ืึทืงืกืขืก ื˜ืขืงืขืก ืื•ื™ืฃ ื“ื™ ืกืขืจื•ื•ืขืจ, ื•ื•ืึธืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืงืจื™ื’ืŸ ื˜ืขืงืขืก ื•ื•ืึธืก ื–ืขื ืขืŸ ื ื™ืฉื˜ ืื•ื ื˜ืขืจื˜ืขื ื™ืง ืฆื• ืึทื ื˜ืคึผืœืขืงื•ื ื’. AJP ืื™ื– ื’ืขืžื™ื™ื ื˜ ืฆื• ื–ื™ื™ืŸ ืฆื•ื˜ืจื™ื˜ืœืขืš ื‘ืœื•ื™ื– ืคึฟืึทืจ ื˜ืจืึทืกื˜ื™ื“ ืกืขืจื•ื•ืขืจืก, ืึธื‘ืขืจ ืื™ืŸ ืคืึทืงื˜, ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืคื•ืŸ Tomcat ื”ืื˜ ืœื•ื™ืคืŸ ื“ื™ ื”ืึทื ื“ืœืขืจ ืื•ื™ืฃ ืึทืœืข ื ืขืฅ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ืื•ืŸ ืื ื’ืขื ื•ืžืขืŸ ืจื™ืงื•ื•ืขืก ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ. ืึทืงืกืขืก ืื™ื– ืžืขื’ืœืขืš ืฆื• ืงื™ื™ืŸ ื•ื•ืขื‘ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ื˜ืขืงืขืก, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ื“ื™ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ WEB-INF, META-INF ืื•ืŸ ืงื™ื™ืŸ ืื ื“ืขืจืข ื“ื™ืจืขืงื˜ืขืจื™ื– ืฆื•ื’ืขืฉื˜ืขืœื˜ ื“ื•ืจืš ืึท ืจื•ืคืŸ ืฆื• ServletContext.getResourceAsStream(). AJP ืื•ื™ืš ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื ื•ืฆืŸ ืงื™ื™ืŸ ื˜ืขืงืข ืื™ืŸ ื“ื™ืจืขืงื˜ืขืจื™ื– ืฆื•ื˜ืจื™ื˜ืœืขืš ืฆื• ื“ื™ ื•ื•ืขื‘ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ื•ื•ื™ ืึท JSP ืฉืจื™ืคื˜.

ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ืืจื•ื™ืก ื–ื™ื ื˜ ื“ื™ Tomcat 13.x ืฆื•ื•ื™ื™ึทื’ ื‘ืืคืจื™ื™ื˜ 6 ื™ืึธืจ ืฆื•ืจื™ืง. ืื™ืŸ ื“ืขืจืฆื• ืฆื• ื“ื™ Tomcat ืคึผืจืึธื‘ืœืขื ื–ื™ืš ืึทืคืขืงืฅ ืื•ืŸ ืคึผืจืึธื“ื•ืงื˜ืŸ ื•ื•ืึธืก ื ื•ืฆืŸ ืขืก, ืึทื–ืึท ื•ื•ื™ Red Hat JBoss Web Server (JWS), JBoss Enterprise Application Platform (EAP), ื•ื•ื™ ื’ืขื–ื•ื ื˜-ืงืึทื ื˜ื™ื™ื ื“ ื•ื•ืขื‘ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื•ื•ืึธืก ื ื•ืฆืŸ ืคืจื™ืœื™ื ื’ ืฉื˜ื™ื•ื•ืœ. ืขื ืœืขื›ืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2020-1745) ืคืึธืจืฉื˜ืขืœืŸ ืื™ืŸ ื“ื™ ื•ื•ืขื‘ ืกืขืจื•ื•ืขืจ ื•ื ื“ืขืจื˜ืึธื•ื•, ื’ืขื•ื•ื™ื™ื ื˜ ืื™ืŸ ื“ื™ Wildfly ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืกืขืจื•ื•ืขืจ. ืื™ืŸ JBoss ืื•ืŸ Wildfly, AJP ืื™ื– ืขื ื™ื™ื‘ืึทืœื“ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜ ื‘ืœื•ื™ื– ืื™ืŸ ืกื˜ืึทื ื“ืึทืœืึธื ืข-full-ha.xml, ืกื˜ืึทื ื“ืึทืœืึธื ืข-ha.xml ืื•ืŸ ha/full-ha ืคึผืจืึธื•ืคื™ื™ืœื– ืื™ืŸ domain.xml. ืื™ืŸ ืคืจื™ืœื™ื ื’ ืฉื˜ื™ื•ื•ืœ, AJP ืฉื˜ื™ืฆืŸ ืื™ื– ืคืึทืจืงืจื™ืคึผืœื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜. ื“ืขืจื•ื•ื™ื™ึทืœ, ืคืึทืจืฉื™ื“ืขื ืข ื’ืจื•ืคึผืขืก ื”ืึธื‘ืŸ ืฆื•ื’ืขื’ืจื™ื™ื˜ ืžืขืจ ื•ื•ื™ ืึท ื˜ื•ืฅ ืืจื‘ืขื˜ืŸ ื‘ื™ื™ืฉืคื™ืœืŸ ืคื•ืŸ ืขืงืกืคึผืœื•ื™ืฅ (
1,
2,
3,
4,
5,
6,
7,
8,
9,
10,
11).

ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ Tomcat ืจื™ืœื™ืกื™ื– 9.0.31, 8.5.51 ะธ 7.0.100 (ื•ื™ืฉืึทืœื˜ ืคื•ืŸ ื“ื™ 6.x ืฆื•ื•ื™ื™ึทื’ ืึธืคึผื’ืขืฉื˜ืขืœื˜). ืื™ืจ ืงืขื ืขืŸ ืฉืคึผื•ืจ ื“ื™ ืึทื•ื•ื™ื™ืœืึทื‘ื™ืœืึทื˜ื™ ืคื•ืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืื™ืŸ ืคืึทืจืฉืคึผืจื™ื™ื˜ื•ื ื’ ืงื™ืฅ ืื•ื™ืฃ ื“ื™ ื‘ืœืขื˜ืขืจ: ื“ืขื‘ื™ืึทืŸ, ื•ื‘ื•ื ื˜ื•, rhel, ืคืขื“ืึธืจืึท, sususe, FreeBSD. ื•ื•ื™ ืึท ื•ื•ืึธืจืงืึทืจืึธื•ื ื“, ืื™ืจ ืงืขื ืขืŸ ื“ื™ืกื™ื™ื‘ืึทืœ ื“ื™ Tomcat AJP ืงืึทื ืขืงื˜ืขืจ ื“ื™ื ืกื˜ (ื‘ื™ื ื“ืŸ ืึท ืฆื•ื’ืขื”ืขืจื˜ ื›ืึธืœืขืœ ืฆื• ืœืึธืงืึทืœื”ืึธืกื˜ ืึธื“ืขืจ ื‘ืึทืžืขืจืงืŸ ื“ื™ ืฉื•ืจื” ืžื™ื˜ ืงืึทื ืขืงื˜ืขืจ ืคึผืึธืจื˜ = "8009") ืื•ื™ื‘ ืขืก ืื™ื– ื ื™ื˜ ื“ืืจืฃ, ืึธื“ืขืจ ื ื™ื’ืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ื™ื“ ืึทืงืกืขืก ื ื™ืฆืŸ ื“ื™ "ืกื•ื“" ืื•ืŸ "ืึทื“ืจืขืก" ืึทื˜ืจื™ื‘ื™ื•ืฅ, ืื•ื™ื‘ ื“ื™ ืกืขืจื•ื•ื™ืก ืื™ื– ื’ืขื ื™ืฆื˜ ืฆื• ื™ื ื˜ืขืจืึทืงื˜ ืžื™ื˜ ืื ื“ืขืจืข ืกืขืจื•ื•ืขืจืก ืื•ืŸ ืคึผืจืึทืงืกื™ื– ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ mod_jk ืื•ืŸ mod_proxy_ajp (ืžืึธื“_ืงืœืึทืกื˜ืขืจ ืฉื˜ื™ืฆื˜ ื ื™ืฉื˜ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ).

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’