Jenkins Plugins ¶à¸öÇå¾²Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-03-11

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-2159£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2138£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2144£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2158£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2134£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2135£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


CryptoMove Plugin 0.1.33ºÍ¸üÔç°æ±¾

Cobertura Plugin 1.15ºÍ¸üÔç°æ±¾

Rundeck Plugin 3.6.6ºÍ¸üÔç°æ±¾

Literate Plugin 1.0ºÍ¸üÔçµÄ°æ±¾

Script Security Plugin 1.70ºÍ¸üÔç°æ±¾


Îó²î¸ÅÊö


CloudBees Jenkins£¨Hudson Labs£©ÊÇÃÀ¹úCloudBees¹«Ë¾µÄÒ»Ì×»ùÓÚJava¿ª·¢µÄÒ»Á¬¼¯³É¹¤¾ß¡£ ¡£¡£¡£¸Ã²úÆ·Ö÷ÒªÓÃÓÚ¼à¿ØÒ»Á¬µÄÈí¼þ°æ±¾Ðû²¼/²âÊÔÏîÄ¿ºÍһЩ׼ʱִÐеÄʹÃü¡£ ¡£¡£¡£


¿ËÈÕ£¬£¬£¬ £¬£¬JenkinsÐû²¼¹Ù·½Ç徲ͨ¸æ£¬£¬£¬ £¬£¬Jenkins²¿·Ö²å¼þ±£´æ¶à¸öÎó²î£¬£¬£¬ £¬£¬ÆäÖиßΣÎó²î¸ÅÊöÈçÏ£º


CVE-2020-2159 CryptoMove Plugin ÏÂÁî×¢Èë

CryptoMove²å¼þ0.1.33ºÍ¸üÔç°æ±¾ÔÊÐí½«OSÏÂÁîµÄÉèÖÃ×÷ΪÆä¹¹½¨°ì·¨ÉèÖõÄÒ»²¿·ÖÖ´ÐС£ ¡£¡£¡£

¸ÃÏÂÁ×÷ΪÔËÐÐJenkinsµÄOSÓû§ÕÊ»§ÔÚJenkinsÖ÷ЧÀÍÆ÷ÉÏÖ´ÐУ¬£¬£¬ £¬£¬´Ó¶øÔÊÐí¾ßÓÐJob/ConfigureȨÏÞµÄÓû§ÔÚJenkinsÖ÷ЧÀÍÆ÷ÉÏÖ´ÐÐí§ÒâOSÏÂÁî¡£ ¡£¡£¡£

×èÖ¹±¾Í¨¸æÐû²¼Ö®Ê±£¬£¬£¬ £¬£¬ÉÐÎÞÐÞ¸´³ÌÐò¡£ ¡£¡£¡£


CVE-2020-2138 Cobertura Plugin XXE

Cobertura²å¼þ1.15ºÍ¸üÔç°æ±¾Ã»ÓÐÉèÖÃÆäXMLÆÊÎöÆ÷À´±ÜÃâXMLÍⲿʵÌ壨XXE£©¹¥»÷¡£ ¡£¡£¡£

ÕâʹÓû§Äܹ»¿ØÖÆ¡°Ðû²¼CoberturaÁýÕÖÂʱ¨¸æ¡±¹¹½¨ºó°ì·¨µÄÊäÈëÎļþ£¬£¬£¬ £¬£¬ÒÔÈÃJenkinsÆÊÎöÖÆ×÷µÄÎļþ£¬£¬£¬ £¬£¬¸ÃÎļþʹÓÃÍⲿʵÌå´ÓJenkinsÖ÷ЧÀÍÆ÷»òЧÀÍÆ÷¶ËÇëÇóαÔìÖÐÌáÈ¡ÉñÃØ¡£ ¡£¡£¡£

Cobertura²å¼þ1.16ΪÆäXMLÆÊÎöÆ÷½ûÓÃÁËÍⲿʵÌåÆÊÎö¡£ ¡£¡£¡£   

 

CVE-2020-2144 Rundeck Plugin XXE

Rundeck²å¼þ3.6.6ºÍ¸üÔç°æ±¾Ã»ÓÐÉèÖÃÆäXMLÆÊÎöÆ÷À´±ÜÃâXMLÍⲿʵÌ壨XXE£©¹¥»÷¡£ ¡£¡£¡£

ÕâÔÊÐí¾ßÓС°×ÜÌå/¶ÁÈ¡¡±»á¼ûȨÏÞµÄÓû§ÈÃJenkinsʹÓÃXMLÊý¾ÝÆÊÎö¾­ÓÉÈ«ÐÄÉè¼ÆµÄHTTPÇëÇ󣬣¬£¬ £¬£¬¸ÃXMLÇëÇóʹÓÃÍⲿʵÌå´ÓJenkinsÖ÷ЧÀÍÆ÷»òЧÀÍÆ÷¶ËÇëÇóαÔìÖÐÌáÈ¡ÉñÃØ¡£ ¡£¡£¡£

Rundeck²å¼þ3.6.7ΪÆäXMLÆÊÎöÆ÷½ûÓÃÁËÍⲿʵÌåÆÊÎö¡£ ¡£¡£¡£   

 

CVE-2020-2158 Literate Plugin Ô¶³Ì´úÂëÖ´ÐÐ

Literate Plugin 1.0ºÍ¸üÔçµÄ°æ±¾Ã»ÓÐÉèÖÃÆäYAMLÆÊÎöÆ÷À´±ÜÃâʵÀý»¯í§ÒâÀàÐÍ¡£ ¡£¡£¡£

Õâµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬ £¬£¬Óû§¿ÉÒÔʹÓøÃÎó²îÏòLiterate PluginµÄ¹¹½¨°ì·¨ÌṩYAMLÊäÈëÎļþ¡£ ¡£¡£¡£

×èÖ¹±¾Í¨¸æÐû²¼Ö®ÈÕ£¬£¬£¬ £¬£¬ÉÐÎÞÐÞ¸´³ÌÐò¡£ ¡£¡£¡£


CVE-2020-2134, CVE-2020-2135 Script Security Plugin ɳºÐÈÆ¹ý

¿ÉÒÔͨ¹ýÒÔÏ·½·¨À´¹æ±ÜScript Security Plugin 1.70ºÍ¸üÔç°æ±¾ÖеÄɳºÐ±£»£»£»¤£º

È«ÐĽṹµÄ½á¹¹º¯ÊýŲÓúÍÖ÷Ì壨ÓÉÓÚSECURITY-582µÄ²»ÍêÕûÐÞ¸´£©

È«ÐÄÉè¼ÆµÄÒªÁìŲÓÃʵÏÖGroovyInterceptableµÄ¹¤¾ß

Õâʹ¹¥»÷ÕßÄܹ»ÔÚJenkinsÖ÷JVMµÄÉÏÏÂÎÄÖÐÖ¸¶¨²¢ÔËÐÐɳºÐ½ÅÔ­À´Ö´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£


Script Security Plugin 1.71¾ßÓÐÆäËûÏÞÖÆºÍ½¡È«ÐÔ¼ì²é£¬£¬£¬ £¬£¬ÒÔÈ·±£ÔÚûÓб»É³Ïä×èµ²µÄÇéÐÎÏÂÎÞ·¨½á¹¹³¬µÈ½á¹¹º¯Êý¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬Ëü»¹×èµ²¶ÔʵÏÖGroovyInterceptableµÄ¹¤¾ßµÄÒªÁìŲÓ㬣¬£¬ £¬£¬×÷Ϊ¶ÔGroovyObject££invokeMethod£¨String£¬£¬£¬ £¬£¬Object£©µÄŲÓ㬣¬£¬ £¬£¬¸Ã¹¤¾ßÊÇÁÐÈëºÚÃûµ¥µÄÒªÁì¡£ ¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPoC/EXP¡£ ¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ²¿·Ö²å¼þÒѸüУ¬£¬£¬ £¬£¬»ñÈ¡Á´½Ó£ºhttps://jenkins.io/security/advisory/2020-03-09/¡£ ¡£¡£¡£Çëʵʱ¸üвå¼þµ½Èçϰ汾£º

CryptoMove Plugin ÔÝÎÞ²¹¶¡

Literate Plugin ÔÝÎÞ²¹¶¡

Cobertura Plugin Éý¼¶µ½ 1.16°æ±¾

Rundeck Plugin Éý¼¶µ½ 3.6.7°æ±¾

Script Security Plugin Éý¼¶µ½ 1.71°æ±¾


²Î¿¼Á´½Ó


https://jenkins.io/security/advisory/2020-03-09/