Apache Tomcatã«ãããæ å ±æ¼ããã®èå¼±æ§ï¼CVE-2020-1938ï¼ã«ã¤ãã¦ã®æ¤è¨¼ã¬ãã¼ã
2020/03/09
2020/03/11 æ´æ°
2020/03/16 æ´æ°
æ¾æ¬ æä¹ãä¸å æ¸ä¸é
2020å¹´2æ24æ¥ã«Apache Software Foundationãå ¬è¡¨ãããApache Tomcatã«ãããèå¼±æ§ï¼CVE-2020-1938ï¼ã«ã¤ãã¦ã®æ¤è¨¼ãå®æ½ããèå¼±æ§ã®æªç¨ãå¯è½ã§ãããã¨ã確èªãã¾ããã
1. æ¬èå¼±æ§ã®æ¦è¦
ãApache Tomcatãã¯ãApache Software Foundationã«ãã£ã¦æä¾ããã¦ããããªã¼ãã³ã½ã¼ã¹ã®ãµã¼ãã¬ããã³ã³ããã§ããApache Software Foundationã«ãããApache Tomcatã«ã¯ãæªæã®ããAJP(Apache JServ Protocol)ãªã¯ã¨ã¹ããéä¿¡ãããã¨ã§ããªã¢ã¼ãããã®æ å ±çªåãå¯è½ã¨ãªãèå¼±æ§ï¼CVE-2020-1938ï¼ãåå¨ãããã¨ãå ±åããã¾ããã[1]
æ¬èå¼±æ§ã¯ãAJPã«ãããAttributeã«é¢ããé©åãªå¦çãè¡ãããªããã¨ã«èµ·å ãã¾ãããã®èå¼±æ§ãæªç¨ãããå ´åããªã¢ã¼ãã®æ»æè
ãä»»æã®ãã¡ã¤ã«ãçªåã§ããå¯è½æ§ãããã¾ãã
ã¾ããWebã¢ããªã±ã¼ã·ã§ã³ããµã¼ãã¼ã¸ã®ãã¡ã¤ã«ã¢ãããã¼ããä¿åã許å¯ãã¦ããå ´åããªã¢ã¼ãããä»»æã®ã³ã¼ããå®è¡ãããå¯è½æ§ãããã¾ãã[2]
å³1. æ¬èå¼±æ§ãæªç¨ããæ»æã®ä¾
å³1ã¯ãæ¬èå¼±æ§ã«å¯¾ããæ»æã®ä¸ä¾ã¨ãã¦ãèå¼±æ§ãå«ãApache Tomcatãµã¼ãã¼ã«å¯¾ããå¤é¨ã®æ»æè ãä¸æ£ãªAJPãªã¯ã¨ã¹ããéä¿¡ãã¦ãµã¼ãã¼ä¸ã®ãã¡ã¤ã«ãçªåããæ»æä¾ã示ãã¦ãã¾ãã
2. æ¬èå¼±æ§ã®å½±é¿ãåããç°å¢
æ¬èå¼±æ§ã®å½±é¿ãåããå¯è½æ§ããããã¼ã¸ã§ã³ã¯ä»¥ä¸ã®éãã§ãã[3]
- Apache Tomcat 7.0.0ãã7.0.99
- Apache Tomcat 8.5.0ãã8.5.50
- Apache Tomcat 9.0.0.M1ãã9.0.30
3. æ¬èå¼±æ§ãå©ç¨ããæ»æã®æ¤è¨¼
æ¦å¿µå®è¨¼ã³ã¼ããç¨ãã¦æ¬èå¼±æ§ã«å¯¾ããæ»æã試è¡ããèå¼±æ§ã®æªç¨ãå¯è½ã§ãããã¨ãæ¤è¨¼ãã¾ããã
3.1. æ¤è¨¼ç°å¢
çä¼¼æ»æè | ç似被害è | |
---|---|---|
OS | Kali Linux 2018.01 64bit | Ubuntu 18.04.2 64bit |
ã¢ããªã±ã¼ã·ã§ã³ | æ¦å¿µå®è¨¼ã³ã¼ã | Apache Tomcat 8.5.32 |
3.2. æ»æææ³
ã¾ããèå¼±æ§ãåå¨ããApache Tomcatã®AJPãããã³ã«éä¿¡ãåãä»ãããã¼ãï¼ä¾ï¼TCP 8009ï¼ã«å¯¾ãã¦ä¸æ£ãªAJPãªã¯ã¨ã¹ããéä¿¡ããWebã¢ããªã±ã¼ã·ã§ã³ã®ã«ã¼ããã£ã¬ã¯ããªã«ãããã¡ã¤ã«ã®èªã¿åããå¯è½ãªãã¨ã確èªãã¾ãã
å³2. æ¦å¿µå®è¨¼ã³ã¼ãã®ãªã¯ã¨ã¹ãã¨ãã®ã¬ã¹ãã³ã¹
å³2ã¯ãæ»æ対象ãµã¼ãã¼ã«å¯¾ããæ¦å¿µå®è¨¼ã³ã¼ãã®å®è¡ã¨ãæ»æ対象ãµã¼ãã¼ããã®ã¬ã¹ãã³ã¹ã§ãã赤ç·ã«ã¦ç¤ºãã¦ããéããWebã¢ããªã±ã¼ã·ã§ã³ã®ã«ã¼ããã£ã¬ã¯ããªã«ããweb.xmlãã¡ã¤ã«ã®å 容ããªã¢ã¼ãããåå¾ã§ãããã¨ã確èªã§ãã¾ããã
ããã«ãæ»æ対象ãµã¼ãã¼ä¸ã®Webã¢ããªã±ã¼ã·ã§ã³ããã¡ã¤ã«ã¢ãããã¼ããä¿åã許å¯ãã¦ããå ´åãæ»æè ããªã¢ã¼ãããä»»æã®ã³ã¼ããå®è¡ããå¯è½æ§ãããã¾ããããã¯ãæ¬èå¼±æ§ã®æªç¨ã«ããèªã¿åºããããã¡ã¤ã«ãJSPãã¡ã¤ã«ã¨ãã¦å¦çãããå®è¡ãããæ©è½ã«èµ·å ãã¦ãã¾ãããã®ããããããããæ£å½ãªãã¡ã¤ã«ã«è¦ããããJSPãã¡ã¤ã«ããµã¼ãã¼ä¸ã«ã¢ãããã¼ããããããèªã¿åºããã¨ã«ããããªã¢ã¼ãããä»»æã®ã³ã¼ããå®è¡ã§ããå¯è½æ§ãããã¾ãã
ä»åã®æ¤è¨¼ã§ã¯ãæ»æ対象ãµã¼ãã¼ä¸ã®/etc/passwdã表示ããããè¨è¿°ããJSPãã¡ã¤ã«ãpasswd.txtã¨ãããã¡ã¤ã«åã§ãããããã¢ãããã¼ããã¦ãããæ¦å¿µå®è¨¼ã³ã¼ããå©ç¨ãã¦èªã¿åããã¨ã«ãã£ã¦ããªã¢ã¼ãããã®ã³ã¼ãå®è¡ã試ã¿ã¾ãã
3.3. æ¤è¨¼çµæ
å³3ã«ç¤ºãçµæã®éããæ»æ対象ã®ãµã¼ãã¼ã«å¯¾ãã¦æ»æè ãµã¼ãã¼ããAJPãªã¯ã¨ã¹ããéä¿¡ãããã¨ã§ãæ»æ対象ãµã¼ãã¼ä¸ã®/etc/passwdã表示ããã³ã¼ãããªã¢ã¼ãããå®è¡ã§ãã¾ãããæ»æè ãµã¼ãã¼ããAJPãªã¯ã¨ã¹ããåãã¦èªã¿åºãããpasswd.txtãJSPã³ã¼ãã¨ãã¦è§£éãããæ»æ対象ãµã¼ãã¼ä¸ã§å®è¡ããããã¨ã«ããããªã¢ã¼ããã/etc/passwdã®å 容ãåå¾ã§ãã¦ãã¾ãã
å³3. æ»æ対象ã®ãµã¼ãã¼ä¸ã§æ»æã³ã¼ãã®å®è¡ã«æåããçµæã確èª
4. æ¬èå¼±æ§ã«å¯¾ãã対ç
4.1. ç¾å¨æ¨å¥¨ããã¦ãã対ç
2020å¹´3æ9æ¥ç¾å¨ãApache Software Foundationããæ¬èå¼±æ§ã®ä¿®æ£ãã¼ã¸ã§ã³ãæä¾ããã¦ãã¾ãã[2]
- Apache Tomcat 7.0.100
- Apache Tomcat 8.5.51
- Apache Tomcat 9.0.31
ä¿®æ£ãã¼ã¸ã§ã³ã¸ã®ã¢ãããã¼ãã®å®æ½ãé£ããå ´åã¯ã以ä¸ã®å¯¾çãå®æ½ãããã¨ã§æ¬èå¼±æ§ã®å½±é¿ãåé¿å¯è½ã§ãã[2]
- AJPãä¸è¦ãªå ´åã¯ãç¡å¹ã«ãã
- AJPãå¿ è¦ãªå ´åã¯ãã¢ã¯ã»ã¹å¶éãè¨å®ãã
4.2. ä¸æ£ã¢ã¯ã»ã¹ç£è¦æ©å¨ã«ãã対ç
4.2.1. å½ç¤¾ã確èªãã¦ããä¸æ£ã¢ã¯ã»ã¹ç£è¦æ©å¨ã®å¯¾å¿ç¶æ³
å製åãã³ãã¼ã®æ¬èå¼±æ§ã¸ã®å¯¾å¿ç¶æ³ã«é¢ããæ å ±ãããã³æ¬æ¤è¨¼ã«ããå製åã§ã®æ¤ç¥çµæã¯ä»¥ä¸ã®éãã§ãã表2ã«å ¬å¼ã·ã°ããã£ã¼ã®æä¾ç¶æ³ãè¨è¼ãã¾ãã
ç¨®å¥ | 製åãã³ãã¼ï¼ 製å |
製åãã³ãã¼æä¾ã®ã·ã°ããã£ã¼ | æ¤ç¥ çµæ |
---|---|---|---|
IDS/IPS | IBM QRader Network Security GX/XGS Series |
ã¡ã¼ã«ã¼ããã®ã·ã°ããã£ã¼ã¯ç¾å¨æªæä¾ã§ãã | - |
McAfee Network Security Platform NS/M Series |
Signature Set 10.8.6.2ï¼ PKTSEARCH: Apache Tomcat AJP Connector Remote Code Execution Vulnerability (CVE-2020-1938) [0x45d45e00] |
â | |
WAF | Imperva SecureSphere |
ã¡ã¼ã«ã¼ããã®ã·ã°ããã£ã¼ã¯ç¾å¨æªæä¾ã§ãã | - |
F5 Networks BIG-IP |
ã¡ã¼ã«ã¼ããã®ã·ã°ããã£ã¼ã¯ç¾å¨æªæä¾ã§ãã | - | |
NGFW | Palo Alto PA Series |
Application and Threat Contentï¼Version 8241 ã»Apache Tomcat Arbitrary Local File Inclusion Vulnerability |
â |
Check Point NGFW Series |
ã¡ã¼ã«ã¼ããã®ã·ã°ããã£ã¼ã¯ç¾å¨æªæä¾ã§ãã | - |
åèæç®
- [1] Apache Tomcat® - Apache Tomcat 9 vulnerabilities
http://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.31 - [2] Apache Tomcat ã®èå¼±æ§ (CVE-2020-1938) ã«é¢ãã注æåèµ·
https://www.jpcert.or.jp/at/2020/at200009.html - [3] Apache Tomcat ã«ãããèå¼±æ§ï¼CVE-2020-1938ï¼ã«ã¤ãã¦ï¼
IPA ç¬ç«è¡æ¿æ³äºº æ å ±å¦çæ¨é²æ©æ§
https://www.ipa.go.jp/security/ciadr/vul/alert20200225.html
æ©å¨å¥å½ç¤¾å¯¾å¿ãµã¼ãã¹
IDS/IPS
- INTELLILINK IDS/IPSã»ãã¥ãªãã£ç£è¦ã»éç¨ãµã¼ãã¹
http://www.intellilink.co.jp/business/security/scrutiny_01
WAF
- INTELLILINK WAFã»ãã¥ãªãã£ç£è¦ã»éç¨ãµã¼ãã¹
http://www.intellilink.co.jp/business/security/scrutiny_05
NGFW
- INTELLILINK UTMã»ãã¥ãªãã£ç£è¦ã»éç¨ãµã¼ãã¹
http://www.intellilink.co.jp/business/security/scrutiny_06
æ´æ°å±¥æ´
2020/03/09 | åçä½æ |
---|---|
2020/03/11 | ã表2. 製åãã³ãã¼ã«ããã·ã°ããã£ã¼æä¾ç¶æ³ãã®IDS/IPS ã®æ å ±ãæ´æ° |
2020/03/16 | ã表2. 製åãã³ãã¼ã«ããã·ã°ããã£ã¼æä¾ç¶æ³ãã®Palo Altoã®æ å ±ãæ´æ° |
æ¬ä»¶ã«é¢ãããåãåããå
NTTãã¼ã¿å
端æè¡æ ªå¼ä¼ç¤¾
ãåãåãããã©ã¼ã
- â» åè¦æ ¼åãä¼ç¤¾åãå£ä½åã製ååã¯ãå社ã®åæ¨ã¾ãã¯ç»é²åæ¨ã§ãã
Tweet