2020년 4월 8일 수요일

CVE-2020-1938 / Ghostcat / Apache Tomcat

CVE-2020-1938 / Ghostcat / Apache Tomcat


:: 뉴스

아파치 톰캣 AJP 프로토콜에 '고스트캣(GhostCat)' 취약점 발견돼
https://www.dailysecu.com/news/articleView.html?idxno=106713


:: 참고

Ghostcat is a high-risk file read / include vulnerability in Tomcat
https://www.chaitin.cn/en/ghostcat

Apache Tomcat AJP 취약점 보안 조치 권고
https://www.krcert.or.kr/data/secNoticeView.do?bulletin_writing_sequence=35279
https://www.krcert.or.kr/data/secNoticeView.do?bulletin_writing_sequence=35292

Ghostcat : Tomcat-Ajp 프로토콜 취약점 (cve-2020-1938) 주의!
https://blog.alyac.co.kr/2772
Busting Ghostcat: An Analysis of the Apache Tomcat Vulnerability (CVE-2020-1938 and CNVD-2020-10487)


:: 조치

[Tomcat] AJP Protocol "GhostCat" 취약점 발견 - CVE-2020-1938
https://blog.naver.com/ncloud24/221835089435


:: 장애처리

Apache Tomcat AJP 보안 취약점(CVE-2020-1938) 조치 중 발생한 문제
https://velog.io/@wosk0106/CVE-2020-1938


:: 탐지



:: 실습

[Tomcat] Ghostcat : CVE-2020-1938
https://ddungkill.tistory.com/129

Ghostcat : Tomcat-Ajp 프로토콜 취약점 (cve-2020-1938)
https://blog.naver.com/isc0304/221832618749


댓글 없음: