← voltar
CVE-2020-1938criticalsob ataque

CVE-2020-1938

100Vexday Risk Score

Corrija agora. Ela está sob exploração confirmada pelo CISA e tem exploit funcional público.

ssvc Actcvss 9.8epss 99%
da publicação à arma0 dias
Publicada no NVD24 de fev.
1ª PoC6 de jun.
metasploit20 de fev.
CISA KEV+738d
probabilidade de exploração
99%top 1% das CVEs
exploração observada
simCISA + VulnCheck
67 exploit(s) público(s)
Ação exigida pela CISAprazo federal: 2022-03-17

Apply updates per vendor instructions.

Pesquisado e redigido com IA a partir do advisory do fornecedor e de análises públicas, com as fontes acima. Confira sempre a versão corrigida no advisory oficial antes de agir.
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Apache · Apache Tomcat
PoCs públicas encontradas67 VexDay Proof
exploitdbVexDay Proofwww.exploit-db.com/exploits/49039exploitdbwww.exploit-db.com/exploits/48143não verificadogithubgithub.com/00theway/Ghostcat-CNVD-2020-10487421githubgithub.com/bkfish/CNVD-2020-10487-Tomcat-Ajp-lfi-Scanner295githubgithub.com/lizhianyuguangming/TomcatScanPro295githubgithub.com/tpt11fb/AttackTomcat257githubgithub.com/sv3nbeast/CVE-2020-1938-Tomact-file_include-file_read54githubgithub.com/xindongzhuaizhuai/CVE-2020-193845githubgithub.com/laolisafe/CVE-2020-193838githubgithub.com/Hancheng-Lei/Hacking-Vulnerability-CVE-2020-1938-Ghostcat20githubgithub.com/woaiqiukui/CVE-2020-1938TomcatAjpScanner14githubgithub.com/fairyming/CVE-2020-193811githubgithub.com/dacade/CVE-2020-19389githubgithub.com/doggycheng/CNVD-2020-104878githubgithub.com/fatal0/tomcat-cve-2020-1938-check7githubgithub.com/w4fz5uck5/CVE-2020-1938-Clean-Version6githubgithub.com/Just1ceP4rtn3r/CVE-2020-1938-Tool3githubgithub.com/YounesTasra-R4z3rSw0rd/CVE-2020-19383githubgithub.com/delsadan/CNVD-2020-10487-Bulk-verification3githubgithub.com/sgdream/CVE-2020-19383githubgithub.com/Warelock/cve-2020-19382githubgithub.com/h7hac9/CVE-2020-19382githubgithub.com/With-fate/CVE-2020-19381githubgithub.com/streghstreek/CVE-2020-19381githubgithub.com/Neko-chanQwQ/CVE-2020-19381githubgithub.com/jptr218/ghostcat1githubgithub.com/shaunmclernon/ghostcat-verification1githubgithub.com/abrewer251/CVE-2020-1938_Ghostcat-PoC0githubgithub.com/whatboxapp/GhostCat-LFI-exp0githubgithub.com/I-Runtime-Error/CVE-2020-19380githubgithub.com/Umesh2807/Ghostcat0githubgithub.com/MateoSec/ghostcatch0githubgithub.com/acodervic/CVE-2020-1938-MSF-MODULE0githubgithub.com/RedTeam-Rediron/CVE-2020-19380githubgithub.com/hopsypopsy8/CVE-2020-1938-Exploitation0githubgithub.com/sangrok-jeon/CVE-2020-1938-Tomcat-AJP-Ghostcat--Analysis0githubgithub.com/aidilzlkfli/Scanning0githubgithub.com/si1ence90/Ghostcat-Tomcat-AJP-Exploit-Py30githubgithub.com/cyberguardsec101-sketch/ghostcat0githubgithub.com/duckpigdog/Tomcat-AJP-CVE-2020-19380vulncheckvulncheck.com/xdb/f69eb1a05f7dnão verificadovulncheckvulncheck.com/xdb/55578bb704d8não verificadovulncheckvulncheck.com/xdb/5af6d84a4f6dnão verificadovulncheckvulncheck.com/xdb/6c2db5dec526não verificadovulncheckvulncheck.com/xdb/396912473adbnão verificadovulncheckvulncheck.com/xdb/7e97ae83b853não verificadovulncheckvulncheck.com/xdb/d0c6a25f782cnão verificadovulncheckvulncheck.com/xdb/f17ae55010e2não verificadovulncheckvulncheck.com/xdb/95c0929acd12não verificadovulncheckvulncheck.com/xdb/b2fb8d964e13não verificadovulncheckvulncheck.com/xdb/bfdfc9be53fbnão verificadovulncheckvulncheck.com/xdb/8d0f432c9695não verificadovulncheckvulncheck.com/xdb/3d964bdfa9c1não verificadovulncheckvulncheck.com/xdb/2b72da94f9cbnão verificadovulncheckvulncheck.com/xdb/12e3fe9de5f4não verificadovulncheckvulncheck.com/xdb/88a7c7ad43aanão verificadovulncheckvulncheck.com/xdb/3ae53715fb1dnão verificadovulncheckvulncheck.com/xdb/fa4d894fa7eenão verificadovulncheckvulncheck.com/xdb/556229dec09anão verificadovulncheckvulncheck.com/xdb/6c96742a5573não verificadovulncheckvulncheck.com/xdb/5f1c2d2f47d2não verificadovulncheckvulncheck.com/xdb/6c1f1061ba27não verificadovulncheckvulncheck.com/xdb/3f9cae8b4bednão verificadovulncheckvulncheck.com/xdb/cd1d30f59b44não verificadovulncheckvulncheck.com/xdb/d5a0b7acb17cnão verificadovulncheckvulncheck.com/xdb/e20dc1f808b8não verificadovulncheckvulncheck.com/xdb/0abdb0ef5835não verificado
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.