Jenkins Plugins ¶à¸öÇå¾²Îó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-03-11Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-2159£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-2138£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-2144£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-2158£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-2134£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-2135£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
CryptoMove Plugin 0.1.33ºÍ¸üÔç°æ±¾
Cobertura Plugin 1.15ºÍ¸üÔç°æ±¾
Rundeck Plugin 3.6.6ºÍ¸üÔç°æ±¾
Literate Plugin 1.0ºÍ¸üÔçµÄ°æ±¾
Script Security Plugin 1.70ºÍ¸üÔç°æ±¾
Îó²î¸ÅÊö
CloudBees Jenkins£¨Hudson Labs£©ÊÇÃÀ¹úCloudBees¹«Ë¾µÄÒ»Ì×»ùÓÚJava¿ª·¢µÄÒ»Á¬¼¯³É¹¤¾ß¡£¡£¡£¡£¡£¡£¸Ã²úÆ·Ö÷ÒªÓÃÓÚ¼à¿ØÒ»Á¬µÄÈí¼þ°æ±¾Ðû²¼/²âÊÔÏîÄ¿ºÍһЩ׼ʱִÐеÄʹÃü¡£¡£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬£¬£¬JenkinsÐû²¼¹Ù·½Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬Jenkins²¿·Ö²å¼þ±£´æ¶à¸öÎó²î£¬£¬£¬£¬£¬£¬ÆäÖиßΣÎó²î¸ÅÊöÈçÏ£º
CVE-2020-2159 CryptoMove Plugin ÏÂÁî×¢Èë
CryptoMove²å¼þ0.1.33ºÍ¸üÔç°æ±¾ÔÊÐí½«OSÏÂÁîµÄÉèÖÃ×÷ΪÆä¹¹½¨°ì·¨ÉèÖõÄÒ»²¿·ÖÖ´ÐС£¡£¡£¡£¡£¡£
¸ÃÏÂÁ×÷ΪÔËÐÐJenkinsµÄOSÓû§ÕÊ»§ÔÚJenkinsÖ÷ЧÀÍÆ÷ÉÏÖ´ÐУ¬£¬£¬£¬£¬£¬´Ó¶øÔÊÐí¾ßÓÐJob/ConfigureȨÏÞµÄÓû§ÔÚJenkinsÖ÷ЧÀÍÆ÷ÉÏÖ´ÐÐí§ÒâOSÏÂÁî¡£¡£¡£¡£¡£¡£
×èÖ¹±¾Í¨¸æÐû²¼Ö®Ê±£¬£¬£¬£¬£¬£¬ÉÐÎÞÐÞ¸´³ÌÐò¡£¡£¡£¡£¡£¡£
CVE-2020-2138 Cobertura Plugin XXE
Cobertura²å¼þ1.15ºÍ¸üÔç°æ±¾Ã»ÓÐÉèÖÃÆäXMLÆÊÎöÆ÷À´±ÜÃâXMLÍⲿʵÌ壨XXE£©¹¥»÷¡£¡£¡£¡£¡£¡£
ÕâʹÓû§Äܹ»¿ØÖÆ¡°Ðû²¼CoberturaÁýÕÖÂʱ¨¸æ¡±¹¹½¨ºó°ì·¨µÄÊäÈëÎļþ£¬£¬£¬£¬£¬£¬ÒÔÈÃJenkinsÆÊÎöÖÆ×÷µÄÎļþ£¬£¬£¬£¬£¬£¬¸ÃÎļþʹÓÃÍⲿʵÌå´ÓJenkinsÖ÷ЧÀÍÆ÷»òЧÀÍÆ÷¶ËÇëÇóαÔìÖÐÌáÈ¡ÉñÃØ¡£¡£¡£¡£¡£¡£
Cobertura²å¼þ1.16ΪÆäXMLÆÊÎöÆ÷½ûÓÃÁËÍⲿʵÌåÆÊÎö¡£¡£¡£¡£¡£¡£
CVE-2020-2144 Rundeck Plugin XXE
Rundeck²å¼þ3.6.6ºÍ¸üÔç°æ±¾Ã»ÓÐÉèÖÃÆäXMLÆÊÎöÆ÷À´±ÜÃâXMLÍⲿʵÌ壨XXE£©¹¥»÷¡£¡£¡£¡£¡£¡£
ÕâÔÊÐí¾ßÓС°×ÜÌå/¶ÁÈ¡¡±»á¼ûȨÏÞµÄÓû§ÈÃJenkinsʹÓÃXMLÊý¾ÝÆÊÎö¾ÓÉÈ«ÐÄÉè¼ÆµÄHTTPÇëÇ󣬣¬£¬£¬£¬£¬¸ÃXMLÇëÇóʹÓÃÍⲿʵÌå´ÓJenkinsÖ÷ЧÀÍÆ÷»òЧÀÍÆ÷¶ËÇëÇóαÔìÖÐÌáÈ¡ÉñÃØ¡£¡£¡£¡£¡£¡£
Rundeck²å¼þ3.6.7ΪÆäXMLÆÊÎöÆ÷½ûÓÃÁËÍⲿʵÌåÆÊÎö¡£¡£¡£¡£¡£¡£
CVE-2020-2158 Literate Plugin Ô¶³Ì´úÂëÖ´ÐÐ
Literate Plugin 1.0ºÍ¸üÔçµÄ°æ±¾Ã»ÓÐÉèÖÃÆäYAMLÆÊÎöÆ÷À´±ÜÃâʵÀý»¯í§ÒâÀàÐÍ¡£¡£¡£¡£¡£¡£
Õâµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬Óû§¿ÉÒÔʹÓøÃÎó²îÏòLiterate PluginµÄ¹¹½¨°ì·¨ÌṩYAMLÊäÈëÎļþ¡£¡£¡£¡£¡£¡£
×èÖ¹±¾Í¨¸æÐû²¼Ö®ÈÕ£¬£¬£¬£¬£¬£¬ÉÐÎÞÐÞ¸´³ÌÐò¡£¡£¡£¡£¡£¡£
CVE-2020-2134, CVE-2020-2135 Script Security Plugin ɳºÐÈÆ¹ý
¿ÉÒÔͨ¹ýÒÔÏ·½·¨À´¹æ±ÜScript Security Plugin 1.70ºÍ¸üÔç°æ±¾ÖеÄɳºÐ±£»£»£»¤£º
È«ÐĽṹµÄ½á¹¹º¯ÊýŲÓúÍÖ÷Ì壨ÓÉÓÚSECURITY-582µÄ²»ÍêÕûÐÞ¸´£©
È«ÐÄÉè¼ÆµÄÒªÁìŲÓÃʵÏÖGroovyInterceptableµÄ¹¤¾ß
Õâʹ¹¥»÷ÕßÄܹ»ÔÚJenkinsÖ÷JVMµÄÉÏÏÂÎÄÖÐÖ¸¶¨²¢ÔËÐÐɳºÐ½ÅÔÀ´Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
Script Security Plugin 1.71¾ßÓÐÆäËûÏÞÖÆºÍ½¡È«ÐÔ¼ì²é£¬£¬£¬£¬£¬£¬ÒÔÈ·±£ÔÚûÓб»É³Ïä×èµ²µÄÇéÐÎÏÂÎÞ·¨½á¹¹³¬µÈ½á¹¹º¯Êý¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬Ëü»¹×èµ²¶ÔʵÏÖGroovyInterceptableµÄ¹¤¾ßµÄÒªÁìŲÓ㬣¬£¬£¬£¬£¬×÷Ϊ¶ÔGroovyObject££invokeMethod£¨String£¬£¬£¬£¬£¬£¬Object£©µÄŲÓ㬣¬£¬£¬£¬£¬¸Ã¹¤¾ßÊÇÁÐÈëºÚÃûµ¥µÄÒªÁì¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ²¿·Ö²å¼þÒѸüУ¬£¬£¬£¬£¬£¬»ñÈ¡Á´½Ó£ºhttps://jenkins.io/security/advisory/2020-03-09/¡£¡£¡£¡£¡£¡£Çëʵʱ¸üвå¼þµ½Èçϰ汾£º
CryptoMove Plugin ÔÝÎÞ²¹¶¡
Literate Plugin ÔÝÎÞ²¹¶¡
Cobertura Plugin Éý¼¶µ½ 1.16°æ±¾
Rundeck Plugin Éý¼¶µ½ 3.6.7°æ±¾
Script Security Plugin Éý¼¶µ½ 1.71°æ±¾
²Î¿¼Á´½Ó
https://jenkins.io/security/advisory/2020-03-09/


¾©¹«Íø°²±¸11010802024551ºÅ