Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2020-1938

Quick assessment

Affected
Apache Apache Tomcat
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Tomcat是美国阿帕奇(Apache)基金会的一款轻量级Web应用服务器。该程序实现了对Servlet和JavaServer Page(JSP)的支持。 Apache Tomcat 7.0.100版本之前的7.版本、8.5.51版本之前的8.版本和9.0.31版本之前的9.*版本中的Tomcat AJP协议存在安全漏洞。攻击者可利用该漏洞读取或包含Tomcat上所有webapp目录下的任意文件,如 webapp 配置文件或源代码等。

AI Predicted 9.8 Difficulty: Easy KEV EPSS 99.27% · P100
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2020-1938

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Apache Tomcat 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache Tomcat是美国阿帕奇(Apache)基金会的一款轻量级Web应用服务器。该程序实现了对Servlet和JavaServer Page(JSP)的支持。 Apache Tomcat 7.0.100版本之前的7.*版本、8.5.51版本之前的8.*版本和9.0.31版本之前的9.*版本中的Tomcat AJP协议存在安全漏洞。攻击者可利用该漏洞读取或包含Tomcat上所有webapp目录下的任意文件,如 webapp 配置文件或源代码等。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Apache Tomcat Apache Tomcat 9.0.0.M1 to 9.0.0.30 -

II. Public POCs for CVE-2020-1938

# POC Description Source Link Shenlong Link
1 None https://github.com/xindongzhuaizhuai/CVE-2020-1938 POC Details
2 CVE-2020-1938 https://github.com/sgdream/CVE-2020-1938 POC Details
3 CNVD-2020-10487(CVE-2020-1938), tomcat ajp 文件读取漏洞poc https://github.com/nibiwodong/CNVD-2020-10487-Tomcat-ajp-POC POC Details
4 Cnvd-2020-10487 / cve-2020-1938, scanner tool https://github.com/bkfish/CNVD-2020-10487-Tomcat-Ajp-lfi-Scanner POC Details
5 CVE-2020-1938漏洞复现 https://github.com/laolisafe/CVE-2020-1938 POC Details
6 None https://github.com/h7hac9/CVE-2020-1938 POC Details
7 Tomcat的文件包含及文件读取漏洞利用POC https://github.com/sv3nbeast/CVE-2020-1938-Tomact-file_include-file_read POC Details
8 在一定条件下可执行命令 https://github.com/fairyming/CVE-2020-1938 POC Details
9 None https://github.com/dacade/CVE-2020-1938 POC Details
10 批量扫描TomcatAJP漏洞 https://github.com/woaiqiukui/CVE-2020-1938TomcatAjpScanner POC Details
11 None https://github.com/fatal0/tomcat-cve-2020-1938-check POC Details
12 CVE-2020-1938 https://github.com/ze0r/GhostCat-LFI-exp POC Details
13 CNVD-2020-10487 OR CVE-2020-1938 批量验证脚本,批量验证,并自动截图,方便提交及复核 https://github.com/delsadan/CNVD-2020-10487-Bulk-verification POC Details
14 Ghostcat read file/code execute,CNVD-2020-10487(CVE-2020-1938) https://github.com/00theway/Ghostcat-CNVD-2020-10487 POC Details
15 Learnings on how to verify if vulnerable to Ghostcat (aka CVE-2020-1938) https://github.com/shaunmclernon/ghostcat-verification POC Details
16 Test Explo for Ghostcat CVE-2020-1938 https://github.com/Zaziki1337/Ghostcat-CVE-2020-1938 POC Details
17 CVE-2020-1938(GhostCat) clean and readable code version https://github.com/w4fz5uck5/CVE-2020-1938-Clean-Version POC Details
18 批量检测幽灵猫漏洞 https://github.com/Just1ceP4rtn3r/CVE-2020-1938-Tool POC Details
19 CVE-2020-1938 / CNVD-2020-1048 Detection Tools https://github.com/doggycheng/CNVD-2020-10487 POC Details
20 This is about CVE-2020-1938 https://github.com/I-Runtime-Error/CVE-2020-1938 POC Details
21 CVE-2020-1938 exploit https://github.com/Umesh2807/Ghostcat POC Details
22 Disables AJP connectors to remediate CVE-2020-1938! https://github.com/MateoSec/ghostcatch POC Details
23 Modified version of auxiliary/admin/http/tomcat_ghostcat, it can Read any file https://github.com/acodervic/CVE-2020-1938-MSF-MODULE POC Details
24 None https://github.com/Hancheng-Lei/Hacking-Vulnerability-CVE-2020-1938-Ghostcat POC Details
25 None https://github.com/streghstreek/CVE-2020-1938 POC Details
26 Scanner for CVE-2020-1938 https://github.com/Neko-chanQwQ/CVE-2020-1938 POC Details
27 An implementation of CVE-2020-1938 https://github.com/jptr218/ghostcat POC Details
28 -H 192.168.1.1-192.168.5.255 https://github.com/einzbernnn/CVE-2020-1938Scan POC Details
29 This is a modified version of the original GhostCat Exploit https://github.com/YounesTasra-R4z3rSw0rd/CVE-2020-1938 POC Details
30 cve-2020-1938 Tomcat-Ajp-lfi.git脚本 https://github.com/Warelock/cve-2020-1938 POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-1938

请登录查看更多情报信息。

Vendor Advisories for CVE-2020-1938 (7)

Mailing List Discussions for CVE-2020-1938 (42)

Other References for CVE-2020-1938 (1)

Same Patch Batch · Apache · 2020-02-24 · 4 CVEs total

CVE-2020-1935 Apache Tomcat 环境问题漏洞
CVE-2019-17569 Apache Tomcat 环境问题漏洞
CVE-2020-1937 Apache Kylin SQL注入漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2020-1938

No comments yet


Leave a comment