Jenkins Plugins ¶à¸öÇå¾²Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-03-11

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-2159£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2138£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2144£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2158£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2134£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2135£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


CryptoMove Plugin 0.1.33ºÍ¸üÔç°æ±¾

Cobertura Plugin 1.15ºÍ¸üÔç°æ±¾

Rundeck Plugin 3.6.6ºÍ¸üÔç°æ±¾

Literate Plugin 1.0ºÍ¸üÔçµÄ°æ±¾

Script Security Plugin 1.70ºÍ¸üÔç°æ±¾


Îó²î¸ÅÊö


CloudBees Jenkins£¨Hudson Labs£©ÊÇÃÀ¹úCloudBees¹«Ë¾µÄÒ»Ì×»ùÓÚJava¿ª·¢µÄÒ»Á¬¼¯³É¹¤¾ß¡£¡£¡£¡£¡£¡£¸Ã²úÆ·Ö÷ÒªÓÃÓÚ¼à¿ØÒ»Á¬µÄÈí¼þ°æ±¾Ðû²¼/²âÊÔÏîÄ¿ºÍһЩ׼ʱִÐеÄʹÃü¡£¡£¡£¡£¡£¡£


¿ËÈÕ£¬£¬£¬£¬£¬JenkinsÐû²¼¹Ù·½Ç徲ͨ¸æ£¬£¬£¬£¬£¬Jenkins²¿·Ö²å¼þ±£´æ¶à¸öÎó²î£¬£¬£¬£¬£¬ÆäÖиßΣÎó²î¸ÅÊöÈçÏ£º


CVE-2020-2159 CryptoMove Plugin ÏÂÁî×¢Èë

CryptoMove²å¼þ0.1.33ºÍ¸üÔç°æ±¾ÔÊÐí½«OSÏÂÁîµÄÉèÖÃ×÷ΪÆä¹¹½¨°ì·¨ÉèÖõÄÒ»²¿·ÖÖ´ÐС£¡£¡£¡£¡£¡£

¸ÃÏÂÁ×÷ΪÔËÐÐJenkinsµÄOSÓû§ÕÊ»§ÔÚJenkinsÖ÷ЧÀÍÆ÷ÉÏÖ´ÐУ¬£¬£¬£¬£¬´Ó¶øÔÊÐí¾ßÓÐJob/ConfigureȨÏÞµÄÓû§ÔÚJenkinsÖ÷ЧÀÍÆ÷ÉÏÖ´ÐÐí§ÒâOSÏÂÁî¡£¡£¡£¡£¡£¡£

×èÖ¹±¾Í¨¸æÐû²¼Ö®Ê±£¬£¬£¬£¬£¬ÉÐÎÞÐÞ¸´³ÌÐò¡£¡£¡£¡£¡£¡£


CVE-2020-2138 Cobertura Plugin XXE

Cobertura²å¼þ1.15ºÍ¸üÔç°æ±¾Ã»ÓÐÉèÖÃÆäXMLÆÊÎöÆ÷À´±ÜÃâXMLÍⲿʵÌ壨XXE£©¹¥»÷¡£¡£¡£¡£¡£¡£

ÕâʹÓû§Äܹ»¿ØÖÆ¡°Ðû²¼CoberturaÁýÕÖÂʱ¨¸æ¡±¹¹½¨ºó°ì·¨µÄÊäÈëÎļþ£¬£¬£¬£¬£¬ÒÔÈÃJenkinsÆÊÎöÖÆ×÷µÄÎļþ£¬£¬£¬£¬£¬¸ÃÎļþʹÓÃÍⲿʵÌå´ÓJenkinsÖ÷ЧÀÍÆ÷»òЧÀÍÆ÷¶ËÇëÇóαÔìÖÐÌáÈ¡ÉñÃØ¡£¡£¡£¡£¡£¡£

Cobertura²å¼þ1.16ΪÆäXMLÆÊÎöÆ÷½ûÓÃÁËÍⲿʵÌåÆÊÎö¡£¡£¡£¡£¡£¡£   

 

CVE-2020-2144 Rundeck Plugin XXE

Rundeck²å¼þ3.6.6ºÍ¸üÔç°æ±¾Ã»ÓÐÉèÖÃÆäXMLÆÊÎöÆ÷À´±ÜÃâXMLÍⲿʵÌ壨XXE£©¹¥»÷¡£¡£¡£¡£¡£¡£

ÕâÔÊÐí¾ßÓС°×ÜÌå/¶ÁÈ¡¡±»á¼ûȨÏÞµÄÓû§ÈÃJenkinsʹÓÃXMLÊý¾ÝÆÊÎö¾­ÓÉÈ«ÐÄÉè¼ÆµÄHTTPÇëÇ󣬣¬£¬£¬£¬¸ÃXMLÇëÇóʹÓÃÍⲿʵÌå´ÓJenkinsÖ÷ЧÀÍÆ÷»òЧÀÍÆ÷¶ËÇëÇóαÔìÖÐÌáÈ¡ÉñÃØ¡£¡£¡£¡£¡£¡£

Rundeck²å¼þ3.6.7ΪÆäXMLÆÊÎöÆ÷½ûÓÃÁËÍⲿʵÌåÆÊÎö¡£¡£¡£¡£¡£¡£   

 

CVE-2020-2158 Literate Plugin Ô¶³Ì´úÂëÖ´ÐÐ

Literate Plugin 1.0ºÍ¸üÔçµÄ°æ±¾Ã»ÓÐÉèÖÃÆäYAMLÆÊÎöÆ÷À´±ÜÃâʵÀý»¯í§ÒâÀàÐÍ¡£¡£¡£¡£¡£¡£

Õâµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬Óû§¿ÉÒÔʹÓøÃÎó²îÏòLiterate PluginµÄ¹¹½¨°ì·¨ÌṩYAMLÊäÈëÎļþ¡£¡£¡£¡£¡£¡£

×èÖ¹±¾Í¨¸æÐû²¼Ö®ÈÕ£¬£¬£¬£¬£¬ÉÐÎÞÐÞ¸´³ÌÐò¡£¡£¡£¡£¡£¡£


CVE-2020-2134, CVE-2020-2135 Script Security Plugin ɳºÐÈÆ¹ý

¿ÉÒÔͨ¹ýÒÔÏ·½·¨À´¹æ±ÜScript Security Plugin 1.70ºÍ¸üÔç°æ±¾ÖеÄɳºÐ±£»£»£»¤£º

È«ÐĽṹµÄ½á¹¹º¯ÊýŲÓúÍÖ÷Ì壨ÓÉÓÚSECURITY-582µÄ²»ÍêÕûÐÞ¸´£©

È«ÐÄÉè¼ÆµÄÒªÁìŲÓÃʵÏÖGroovyInterceptableµÄ¹¤¾ß

Õâʹ¹¥»÷ÕßÄܹ»ÔÚJenkinsÖ÷JVMµÄÉÏÏÂÎÄÖÐÖ¸¶¨²¢ÔËÐÐɳºÐ½ÅÔ­À´Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£


Script Security Plugin 1.71¾ßÓÐÆäËûÏÞÖÆºÍ½¡È«ÐÔ¼ì²é£¬£¬£¬£¬£¬ÒÔÈ·±£ÔÚûÓб»É³Ïä×èµ²µÄÇéÐÎÏÂÎÞ·¨½á¹¹³¬µÈ½á¹¹º¯Êý¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Ëü»¹×èµ²¶ÔʵÏÖGroovyInterceptableµÄ¹¤¾ßµÄÒªÁìŲÓ㬣¬£¬£¬£¬×÷Ϊ¶ÔGroovyObject££invokeMethod£¨String£¬£¬£¬£¬£¬Object£©µÄŲÓ㬣¬£¬£¬£¬¸Ã¹¤¾ßÊÇÁÐÈëºÚÃûµ¥µÄÒªÁì¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ²¿·Ö²å¼þÒѸüУ¬£¬£¬£¬£¬»ñÈ¡Á´½Ó£ºhttps://jenkins.io/security/advisory/2020-03-09/¡£¡£¡£¡£¡£¡£Çëʵʱ¸üвå¼þµ½Èçϰ汾£º

CryptoMove Plugin ÔÝÎÞ²¹¶¡

Literate Plugin ÔÝÎÞ²¹¶¡

Cobertura Plugin Éý¼¶µ½ 1.16°æ±¾

Rundeck Plugin Éý¼¶µ½ 3.6.7°æ±¾

Script Security Plugin Éý¼¶µ½ 1.71°æ±¾


²Î¿¼Á´½Ó


https://jenkins.io/security/advisory/2020-03-09/