← volver
CVE-2020-1938criticalbajo ataque

CVE-2020-1938

100Vexday Risk Score

Corrige ahora. Ella está bajo explotación confirmada por CISA y tiene exploit funcional público.

ssvc Actcvss 9.8epss 99%
de la publicación al arma0 días
Publicada en NVD24 feb
1ª PoC6 jun
metasploit20 feb
CISA KEV+738d
probabilidad de explotación
99%top 1% de las CVE
explotación observada
CISA + VulnCheck
67 exploit(s) público(s)
Acción exigida por CISAplazo federal: 2022-03-17

Apply updates per vendor instructions.

Investigado y redactado con IA a partir del advisory del fabricante y análisis públicos, con las fuentes citadas. Verifica siempre la versión corregida en el advisory oficial antes de actuar.
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Apache · Apache Tomcat
PoCs públicas encontradas67 VexDay Proof
exploitdbVexDay Proofwww.exploit-db.com/exploits/49039exploitdbwww.exploit-db.com/exploits/48143no verificadogithubgithub.com/00theway/Ghostcat-CNVD-2020-10487422githubgithub.com/lizhianyuguangming/TomcatScanPro295githubgithub.com/bkfish/CNVD-2020-10487-Tomcat-Ajp-lfi-Scanner294githubgithub.com/tpt11fb/AttackTomcat257githubgithub.com/sv3nbeast/CVE-2020-1938-Tomact-file_include-file_read54githubgithub.com/xindongzhuaizhuai/CVE-2020-193845githubgithub.com/laolisafe/CVE-2020-193838githubgithub.com/Hancheng-Lei/Hacking-Vulnerability-CVE-2020-1938-Ghostcat21githubgithub.com/woaiqiukui/CVE-2020-1938TomcatAjpScanner14githubgithub.com/fairyming/CVE-2020-193811githubgithub.com/dacade/CVE-2020-19389githubgithub.com/doggycheng/CNVD-2020-104878githubgithub.com/fatal0/tomcat-cve-2020-1938-check7githubgithub.com/w4fz5uck5/CVE-2020-1938-Clean-Version6githubgithub.com/sgdream/CVE-2020-19383githubgithub.com/Just1ceP4rtn3r/CVE-2020-1938-Tool3githubgithub.com/YounesTasra-R4z3rSw0rd/CVE-2020-19383githubgithub.com/delsadan/CNVD-2020-10487-Bulk-verification3githubgithub.com/Warelock/cve-2020-19382githubgithub.com/h7hac9/CVE-2020-19382githubgithub.com/With-fate/CVE-2020-19381githubgithub.com/Neko-chanQwQ/CVE-2020-19381githubgithub.com/streghstreek/CVE-2020-19381githubgithub.com/shaunmclernon/ghostcat-verification1githubgithub.com/jptr218/ghostcat1githubgithub.com/RedTeam-Rediron/CVE-2020-19380githubgithub.com/abrewer251/CVE-2020-1938_Ghostcat-PoC0githubgithub.com/acodervic/CVE-2020-1938-MSF-MODULE0githubgithub.com/MateoSec/ghostcatch0githubgithub.com/Umesh2807/Ghostcat0githubgithub.com/I-Runtime-Error/CVE-2020-19380githubgithub.com/whatboxapp/GhostCat-LFI-exp0githubgithub.com/si1ence90/Ghostcat-Tomcat-AJP-Exploit-Py30githubgithub.com/aidilzlkfli/Scanning0githubgithub.com/cyberguardsec101-sketch/ghostcat0githubgithub.com/duckpigdog/Tomcat-AJP-CVE-2020-19380githubgithub.com/sangrok-jeon/CVE-2020-1938-Tomcat-AJP-Ghostcat--Analysis0githubgithub.com/hopsypopsy8/CVE-2020-1938-Exploitation0vulncheckvulncheck.com/xdb/3f9cae8b4bedno verificadovulncheckvulncheck.com/xdb/7e97ae83b853no verificadovulncheckvulncheck.com/xdb/b2fb8d964e13no verificadovulncheckvulncheck.com/xdb/8d0f432c9695no verificadovulncheckvulncheck.com/xdb/bfdfc9be53fbno verificadovulncheckvulncheck.com/xdb/95c0929acd12no verificadovulncheckvulncheck.com/xdb/12e3fe9de5f4no verificadovulncheckvulncheck.com/xdb/2b72da94f9cbno verificadovulncheckvulncheck.com/xdb/3d964bdfa9c1no verificadovulncheckvulncheck.com/xdb/f17ae55010e2no verificadovulncheckvulncheck.com/xdb/d0c6a25f782cno verificadovulncheckvulncheck.com/xdb/396912473adbno verificadovulncheckvulncheck.com/xdb/6c2db5dec526no verificadovulncheckvulncheck.com/xdb/5af6d84a4f6dno verificadovulncheckvulncheck.com/xdb/55578bb704d8no verificadovulncheckvulncheck.com/xdb/f69eb1a05f7dno verificadovulncheckvulncheck.com/xdb/0abdb0ef5835no verificadovulncheckvulncheck.com/xdb/e20dc1f808b8no verificadovulncheckvulncheck.com/xdb/d5a0b7acb17cno verificadovulncheckvulncheck.com/xdb/88a7c7ad43aano verificadovulncheckvulncheck.com/xdb/3ae53715fb1dno verificadovulncheckvulncheck.com/xdb/fa4d894fa7eeno verificadovulncheckvulncheck.com/xdb/556229dec09ano verificadovulncheckvulncheck.com/xdb/6c96742a5573no verificadovulncheckvulncheck.com/xdb/5f1c2d2f47d2no verificadovulncheckvulncheck.com/xdb/6c1f1061ba27no verificadovulncheckvulncheck.com/xdb/cd1d30f59b44no verificado
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.