Jenkins Plugins ¶à¸öÇå¾²Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-03-11

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-2159£¬ £¬£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2138£¬ £¬£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2144£¬ £¬£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2158£¬ £¬£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2134£¬ £¬£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2135£¬ £¬£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


CryptoMove Plugin 0.1.33ºÍ¸üÔç°æ±¾

Cobertura Plugin 1.15ºÍ¸üÔç°æ±¾

Rundeck Plugin 3.6.6ºÍ¸üÔç°æ±¾

Literate Plugin 1.0ºÍ¸üÔçµÄ°æ±¾

Script Security Plugin 1.70ºÍ¸üÔç°æ±¾


Îó²î¸ÅÊö


CloudBees Jenkins£¨Hudson Labs£©ÊÇÃÀ¹úCloudBees¹«Ë¾µÄÒ»Ì×»ùÓÚJava¿ª·¢µÄÒ»Á¬¼¯³É¹¤¾ß¡£¡£¡£¡£¸Ã²úÆ·Ö÷ÒªÓÃÓÚ¼à¿ØÒ»Á¬µÄÈí¼þ°æ±¾Ðû²¼/²âÊÔÏîÄ¿ºÍһЩ׼ʱִÐеÄʹÃü¡£¡£¡£¡£


¿ËÈÕ£¬ £¬£¬£¬£¬ £¬£¬JenkinsÐû²¼¹Ù·½Ç徲ͨ¸æ£¬ £¬£¬£¬£¬ £¬£¬Jenkins²¿·Ö²å¼þ±£´æ¶à¸öÎó²î£¬ £¬£¬£¬£¬ £¬£¬ÆäÖиßΣÎó²î¸ÅÊöÈçÏ£º


CVE-2020-2159 CryptoMove Plugin ÏÂÁî×¢Èë

CryptoMove²å¼þ0.1.33ºÍ¸üÔç°æ±¾ÔÊÐí½«OSÏÂÁîµÄÉèÖÃ×÷ΪÆä¹¹½¨°ì·¨ÉèÖõÄÒ»²¿·ÖÖ´ÐС£¡£¡£¡£

¸ÃÏÂÁ×÷ΪÔËÐÐJenkinsµÄOSÓû§ÕÊ»§ÔÚJenkinsÖ÷ЧÀÍÆ÷ÉÏÖ´ÐУ¬ £¬£¬£¬£¬ £¬£¬´Ó¶øÔÊÐí¾ßÓÐJob/ConfigureȨÏÞµÄÓû§ÔÚJenkinsÖ÷ЧÀÍÆ÷ÉÏÖ´ÐÐí§ÒâOSÏÂÁî¡£¡£¡£¡£

×èÖ¹±¾Í¨¸æÐû²¼Ö®Ê±£¬ £¬£¬£¬£¬ £¬£¬ÉÐÎÞÐÞ¸´³ÌÐò¡£¡£¡£¡£


CVE-2020-2138 Cobertura Plugin XXE

Cobertura²å¼þ1.15ºÍ¸üÔç°æ±¾Ã»ÓÐÉèÖÃÆäXMLÆÊÎöÆ÷À´±ÜÃâXMLÍⲿʵÌ壨XXE£©¹¥»÷¡£¡£¡£¡£

ÕâʹÓû§Äܹ»¿ØÖÆ¡°Ðû²¼CoberturaÁýÕÖÂʱ¨¸æ¡±¹¹½¨ºó°ì·¨µÄÊäÈëÎļþ£¬ £¬£¬£¬£¬ £¬£¬ÒÔÈÃJenkinsÆÊÎöÖÆ×÷µÄÎļþ£¬ £¬£¬£¬£¬ £¬£¬¸ÃÎļþʹÓÃÍⲿʵÌå´ÓJenkinsÖ÷ЧÀÍÆ÷»òЧÀÍÆ÷¶ËÇëÇóαÔìÖÐÌáÈ¡ÉñÃØ¡£¡£¡£¡£

Cobertura²å¼þ1.16ΪÆäXMLÆÊÎöÆ÷½ûÓÃÁËÍⲿʵÌåÆÊÎö¡£¡£¡£¡£   

 

CVE-2020-2144 Rundeck Plugin XXE

Rundeck²å¼þ3.6.6ºÍ¸üÔç°æ±¾Ã»ÓÐÉèÖÃÆäXMLÆÊÎöÆ÷À´±ÜÃâXMLÍⲿʵÌ壨XXE£©¹¥»÷¡£¡£¡£¡£

ÕâÔÊÐí¾ßÓС°×ÜÌå/¶ÁÈ¡¡±»á¼ûȨÏÞµÄÓû§ÈÃJenkinsʹÓÃXMLÊý¾ÝÆÊÎö¾­ÓÉÈ«ÐÄÉè¼ÆµÄHTTPÇëÇó£¬ £¬£¬£¬£¬ £¬£¬¸ÃXMLÇëÇóʹÓÃÍⲿʵÌå´ÓJenkinsÖ÷ЧÀÍÆ÷»òЧÀÍÆ÷¶ËÇëÇóαÔìÖÐÌáÈ¡ÉñÃØ¡£¡£¡£¡£

Rundeck²å¼þ3.6.7ΪÆäXMLÆÊÎöÆ÷½ûÓÃÁËÍⲿʵÌåÆÊÎö¡£¡£¡£¡£   

 

CVE-2020-2158 Literate Plugin Ô¶³Ì´úÂëÖ´ÐÐ

Literate Plugin 1.0ºÍ¸üÔçµÄ°æ±¾Ã»ÓÐÉèÖÃÆäYAMLÆÊÎöÆ÷À´±ÜÃâʵÀý»¯í§ÒâÀàÐÍ¡£¡£¡£¡£

Õâµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ £¬£¬£¬£¬ £¬£¬Óû§¿ÉÒÔʹÓøÃÎó²îÏòLiterate PluginµÄ¹¹½¨°ì·¨ÌṩYAMLÊäÈëÎļþ¡£¡£¡£¡£

×èÖ¹±¾Í¨¸æÐû²¼Ö®ÈÕ£¬ £¬£¬£¬£¬ £¬£¬ÉÐÎÞÐÞ¸´³ÌÐò¡£¡£¡£¡£


CVE-2020-2134, CVE-2020-2135 Script Security Plugin ɳºÐÈÆ¹ý

¿ÉÒÔͨ¹ýÒÔÏ·½·¨À´¹æ±ÜScript Security Plugin 1.70ºÍ¸üÔç°æ±¾ÖеÄɳºÐ±£»£»£»£»£»£»£»¤£º

È«ÐĽṹµÄ½á¹¹º¯ÊýŲÓúÍÖ÷Ì壨ÓÉÓÚSECURITY-582µÄ²»ÍêÕûÐÞ¸´£©

È«ÐÄÉè¼ÆµÄÒªÁìŲÓÃʵÏÖGroovyInterceptableµÄ¹¤¾ß

Õâʹ¹¥»÷ÕßÄܹ»ÔÚJenkinsÖ÷JVMµÄÉÏÏÂÎÄÖÐÖ¸¶¨²¢ÔËÐÐɳºÐ½ÅÔ­À´Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£


Script Security Plugin 1.71¾ßÓÐÆäËûÏÞÖÆºÍ½¡È«ÐÔ¼ì²é£¬ £¬£¬£¬£¬ £¬£¬ÒÔÈ·±£ÔÚûÓб»É³Ïä×èµ²µÄÇéÐÎÏÂÎÞ·¨½á¹¹³¬µÈ½á¹¹º¯Êý¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬ £¬£¬Ëü»¹×èµ²¶ÔʵÏÖGroovyInterceptableµÄ¹¤¾ßµÄÒªÁìŲÓ㬠£¬£¬£¬£¬ £¬£¬×÷Ϊ¶ÔGroovyObject££invokeMethod£¨String£¬ £¬£¬£¬£¬ £¬£¬Object£©µÄŲÓ㬠£¬£¬£¬£¬ £¬£¬¸Ã¹¤¾ßÊÇÁÐÈëºÚÃûµ¥µÄÒªÁì¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPoC/EXP¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ²¿·Ö²å¼þÒѸüУ¬ £¬£¬£¬£¬ £¬£¬»ñÈ¡Á´½Ó£ºhttps://jenkins.io/security/advisory/2020-03-09/¡£¡£¡£¡£Çëʵʱ¸üвå¼þµ½Èçϰ汾£º

CryptoMove Plugin ÔÝÎÞ²¹¶¡

Literate Plugin ÔÝÎÞ²¹¶¡

Cobertura Plugin Éý¼¶µ½ 1.16°æ±¾

Rundeck Plugin Éý¼¶µ½ 3.6.7°æ±¾

Script Security Plugin Éý¼¶µ½ 1.71°æ±¾


²Î¿¼Á´½Ó


https://jenkins.io/security/advisory/2020-03-09/