Apache Tomcat WebSocket 拒绝服务漏洞 CVE-2020-13935
漏洞描述
漏洞影响
环境搭建
https://github.com/vulhub/vulhub.git
cd vulhub/tomcat/CVE-2020-1938
docker-compose up -d漏洞复现
漏洞利用POC
Last updated
https://github.com/vulhub/vulhub.git
cd vulhub/tomcat/CVE-2020-1938
docker-compose up -dLast updated
go: github.com/gorilla/websocket@v1.4.2: Get "https://proxy.golang.org/github.com/gorilla/websocket/@v/v1.4.2.mod": dial tcp 172.217.160.81:443: connectex: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.需要使用命令切换源
go env -w GOPROXY=https://goproxy.cntcdos ws://192.168.51.133:8080/examples/websocket/echoStreamAnnotation