Jenkins Plugins ¶à¸öÇå¾²Îó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-03-11Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-2159£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-2138£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-2144£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-2158£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-2134£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-2135£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
CryptoMove Plugin 0.1.33ºÍ¸üÔç°æ±¾
Cobertura Plugin 1.15ºÍ¸üÔç°æ±¾
Rundeck Plugin 3.6.6ºÍ¸üÔç°æ±¾
Literate Plugin 1.0ºÍ¸üÔçµÄ°æ±¾
Script Security Plugin 1.70ºÍ¸üÔç°æ±¾
Îó²î¸ÅÊö
CloudBees Jenkins£¨Hudson Labs£©ÊÇÃÀ¹úCloudBees¹«Ë¾µÄÒ»Ì×»ùÓÚJava¿ª·¢µÄÒ»Á¬¼¯³É¹¤¾ß¡£¡£¡£¡£¸Ã²úÆ·Ö÷ÒªÓÃÓÚ¼à¿ØÒ»Á¬µÄÈí¼þ°æ±¾Ðû²¼/²âÊÔÏîÄ¿ºÍһЩ׼ʱִÐеÄʹÃü¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬JenkinsÐû²¼¹Ù·½Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬Jenkins²¿·Ö²å¼þ±£´æ¶à¸öÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäÖиßΣÎó²î¸ÅÊöÈçÏ£º
CVE-2020-2159 CryptoMove Plugin ÏÂÁî×¢Èë
CryptoMove²å¼þ0.1.33ºÍ¸üÔç°æ±¾ÔÊÐí½«OSÏÂÁîµÄÉèÖÃ×÷ΪÆä¹¹½¨°ì·¨ÉèÖõÄÒ»²¿·ÖÖ´ÐС£¡£¡£¡£
¸ÃÏÂÁ×÷ΪÔËÐÐJenkinsµÄOSÓû§ÕÊ»§ÔÚJenkinsÖ÷ЧÀÍÆ÷ÉÏÖ´ÐУ¬£¬£¬£¬£¬£¬£¬´Ó¶øÔÊÐí¾ßÓÐJob/ConfigureȨÏÞµÄÓû§ÔÚJenkinsÖ÷ЧÀÍÆ÷ÉÏÖ´ÐÐí§ÒâOSÏÂÁî¡£¡£¡£¡£
×èÖ¹±¾Í¨¸æÐû²¼Ö®Ê±£¬£¬£¬£¬£¬£¬£¬ÉÐÎÞÐÞ¸´³ÌÐò¡£¡£¡£¡£
CVE-2020-2138 Cobertura Plugin XXE
Cobertura²å¼þ1.15ºÍ¸üÔç°æ±¾Ã»ÓÐÉèÖÃÆäXMLÆÊÎöÆ÷À´±ÜÃâXMLÍⲿʵÌ壨XXE£©¹¥»÷¡£¡£¡£¡£
ÕâʹÓû§Äܹ»¿ØÖÆ¡°Ðû²¼CoberturaÁýÕÖÂʱ¨¸æ¡±¹¹½¨ºó°ì·¨µÄÊäÈëÎļþ£¬£¬£¬£¬£¬£¬£¬ÒÔÈÃJenkinsÆÊÎöÖÆ×÷µÄÎļþ£¬£¬£¬£¬£¬£¬£¬¸ÃÎļþʹÓÃÍⲿʵÌå´ÓJenkinsÖ÷ЧÀÍÆ÷»òЧÀÍÆ÷¶ËÇëÇóαÔìÖÐÌáÈ¡ÉñÃØ¡£¡£¡£¡£
Cobertura²å¼þ1.16ΪÆäXMLÆÊÎöÆ÷½ûÓÃÁËÍⲿʵÌåÆÊÎö¡£¡£¡£¡£
CVE-2020-2144 Rundeck Plugin XXE
Rundeck²å¼þ3.6.6ºÍ¸üÔç°æ±¾Ã»ÓÐÉèÖÃÆäXMLÆÊÎöÆ÷À´±ÜÃâXMLÍⲿʵÌ壨XXE£©¹¥»÷¡£¡£¡£¡£
ÕâÔÊÐí¾ßÓС°×ÜÌå/¶ÁÈ¡¡±»á¼ûȨÏÞµÄÓû§ÈÃJenkinsʹÓÃXMLÊý¾ÝÆÊÎö¾ÓÉÈ«ÐÄÉè¼ÆµÄHTTPÇëÇ󣬣¬£¬£¬£¬£¬£¬¸ÃXMLÇëÇóʹÓÃÍⲿʵÌå´ÓJenkinsÖ÷ЧÀÍÆ÷»òЧÀÍÆ÷¶ËÇëÇóαÔìÖÐÌáÈ¡ÉñÃØ¡£¡£¡£¡£
Rundeck²å¼þ3.6.7ΪÆäXMLÆÊÎöÆ÷½ûÓÃÁËÍⲿʵÌåÆÊÎö¡£¡£¡£¡£
CVE-2020-2158 Literate Plugin Ô¶³Ì´úÂëÖ´ÐÐ
Literate Plugin 1.0ºÍ¸üÔçµÄ°æ±¾Ã»ÓÐÉèÖÃÆäYAMLÆÊÎöÆ÷À´±ÜÃâʵÀý»¯í§ÒâÀàÐÍ¡£¡£¡£¡£
Õâµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬£¬Óû§¿ÉÒÔʹÓøÃÎó²îÏòLiterate PluginµÄ¹¹½¨°ì·¨ÌṩYAMLÊäÈëÎļþ¡£¡£¡£¡£
×èÖ¹±¾Í¨¸æÐû²¼Ö®ÈÕ£¬£¬£¬£¬£¬£¬£¬ÉÐÎÞÐÞ¸´³ÌÐò¡£¡£¡£¡£
CVE-2020-2134, CVE-2020-2135 Script Security Plugin ɳºÐÈÆ¹ý
¿ÉÒÔͨ¹ýÒÔÏ·½·¨À´¹æ±ÜScript Security Plugin 1.70ºÍ¸üÔç°æ±¾ÖеÄɳºÐ±£»£»£»£»£»£»£»¤£º
È«ÐĽṹµÄ½á¹¹º¯ÊýŲÓúÍÖ÷Ì壨ÓÉÓÚSECURITY-582µÄ²»ÍêÕûÐÞ¸´£©
È«ÐÄÉè¼ÆµÄÒªÁìŲÓÃʵÏÖGroovyInterceptableµÄ¹¤¾ß
Õâʹ¹¥»÷ÕßÄܹ»ÔÚJenkinsÖ÷JVMµÄÉÏÏÂÎÄÖÐÖ¸¶¨²¢ÔËÐÐɳºÐ½ÅÔÀ´Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
Script Security Plugin 1.71¾ßÓÐÆäËûÏÞÖÆºÍ½¡È«ÐÔ¼ì²é£¬£¬£¬£¬£¬£¬£¬ÒÔÈ·±£ÔÚûÓб»É³Ïä×èµ²µÄÇéÐÎÏÂÎÞ·¨½á¹¹³¬µÈ½á¹¹º¯Êý¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Ëü»¹×èµ²¶ÔʵÏÖGroovyInterceptableµÄ¹¤¾ßµÄÒªÁìŲÓ㬣¬£¬£¬£¬£¬£¬×÷Ϊ¶ÔGroovyObject££invokeMethod£¨String£¬£¬£¬£¬£¬£¬£¬Object£©µÄŲÓ㬣¬£¬£¬£¬£¬£¬¸Ã¹¤¾ßÊÇÁÐÈëºÚÃûµ¥µÄÒªÁì¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPoC/EXP¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ²¿·Ö²å¼þÒѸüУ¬£¬£¬£¬£¬£¬£¬»ñÈ¡Á´½Ó£ºhttps://jenkins.io/security/advisory/2020-03-09/¡£¡£¡£¡£Çëʵʱ¸üвå¼þµ½Èçϰ汾£º
CryptoMove Plugin ÔÝÎÞ²¹¶¡
Literate Plugin ÔÝÎÞ²¹¶¡
Cobertura Plugin Éý¼¶µ½ 1.16°æ±¾
Rundeck Plugin Éý¼¶µ½ 3.6.7°æ±¾
Script Security Plugin Éý¼¶µ½ 1.71°æ±¾
²Î¿¼Á´½Ó
https://jenkins.io/security/advisory/2020-03-09/