Jenkins Plugins ¶à¸ö°²È«·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-03-11

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-2159£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2138£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2144£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2158£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2134£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2135£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


CryptoMove Plugin 0.1.33ºÍ¸üÔç°æ±¾

Cobertura Plugin 1.15ºÍ¸üÔç°æ±¾

Rundeck Plugin 3.6.6ºÍ¸üÔç°æ±¾

Literate Plugin 1.0ºÍ¸üÔçµÄ°æ±¾

Script Security Plugin 1.70ºÍ¸üÔç°æ±¾


·ì϶¸ÅÊö


CloudBees Jenkins£¨Hudson Labs£©ÊÇÃÀ¹úCloudBees¹«Ë¾µÄÒ»Ì×»ùÓÚJava¿ª·¢µÄ³ÖÐø¼¯³É¹¤¾ß¡£¸Ã²úÆ·ÖØÒªÓÃÓÚ¼à¿Ø³ÖÐøµÄÈí¼þ°æ±¾°ä²¼/²âÊÔÏîÄ¿ºÍһЩ°´Ê±Ö´ÐеŤ×÷¡£


½üÈÕ£¬Jenkins°ä²¼¹Ù·½°²È«¹«¸æ£¬Jenkins²¿ÃŲå¼þ´æÔÚ¶à¸ö·ì϶£¬ÆäÖиßΣ·ì϶¸ÅÊöÈçÏ£º


CVE-2020-2159 CryptoMove Plugin ºÅÁî×¢Èë

CryptoMove²å¼þ0.1.33ºÍ¸üÔç°æ±¾ÔÊÐí½«OSºÅÁîµÄÅäÖÃ×÷ΪÆä¹¹½¨²½ÖèÅäÖõÄÒ»²¿ÃÅÖ´ÐС£

¸ÃºÅÁ×÷ΪÔËÐÐJenkinsµÄOSÓû§ÕÊ»§ÔÚJenkinsÖ÷·þÎñÆ÷ÉÏÖ´ÐУ¬´Ó¶øÔÊÐíÓµÓÐJob/ConfigureȨÏÞµÄÓû§ÔÚJenkinsÖ÷·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâOSºÅÁî¡£

½ØÖÁ±¾²¼¸æ°ä²¼Ö®Ê±£¬ÉÐÎÞ½¨¸´·¨Ê½¡£


CVE-2020-2138 Cobertura Plugin XXE

Cobertura²å¼þ1.15ºÍ¸üÔç°æ±¾Ã»ÓÐÅäÖÃÆäXML½âÎöÆ÷À´Ô¤·ÀXML±í²¿ÊµÌ壨XXE£©¹¥»÷¡£

ÕâʹÓû§¿ÉÄܽÚÔì¡°°ä²¼Cobertura¸²¸ÇÂʻ㱨¡±¹¹½¨ºó²½ÖèµÄÊäÈëÎļþ£¬ÒÔÈÃJenkins½âÎöÔì×÷µÄÎļþ£¬¸ÃÎļþʹÓÃ±í²¿ÊµÌå´ÓJenkinsÖ÷·þÎñÆ÷»ò·þÎñÆ÷¶ËÒªÇóαÔìÖÐÌáÈ¡°ÂÃØ¡£

Cobertura²å¼þ1.16ΪÆäXML½âÎöÆ÷½ûÓÃÁË±í²¿ÊµÌå½âÎö¡£   

 

CVE-2020-2144 Rundeck Plugin XXE

Rundeck²å¼þ3.6.6ºÍ¸üÔç°æ±¾Ã»ÓÐÅäÖÃÆäXML½âÎöÆ÷À´Ô¤·ÀXML±í²¿ÊµÌ壨XXE£©¹¥»÷¡£

ÕâÔÊÐí¾ßÓÓ×°×ÜÌå/¶ÁÈ¡¡±½Ó¼ûȨÏÞµÄÓû§ÈÃJenkinsʹÓÃXMLÊý¾Ý½âÎö¾­¹ý¾«ÐÄÉè¼ÆµÄHTTPÒªÇ󣬸ÃXMLÒªÇóʹÓÃ±í²¿ÊµÌå´ÓJenkinsÖ÷·þÎñÆ÷»ò·þÎñÆ÷¶ËÒªÇóαÔìÖÐÌáÈ¡»úÃÜ¡£

Rundeck²å¼þ3.6.7ΪÆäXML½âÎöÆ÷½ûÓÃÁË±í²¿ÊµÌå½âÎö¡£   

 

CVE-2020-2158 Literate Plugin Ô¶³Ì´úÂëÖ´ÐÐ

Literate Plugin 1.0ºÍ¸üÔçµÄ°æ±¾Ã»ÓÐÅäÖÃÆäYAML½âÎöÆ÷À´Ô¤·ÀÊ·ý»¯ËÁÒâÀàÐÍ¡£

Õâµ¼ÖÂÔ¶³Ì´úÂëÖ´Ðзì϶£¬Óû§Äܹ»ÀûÓø÷ì϶ÏòLiterate PluginµÄ¹¹½¨²½ÖèÌṩYAMLÊäÈëÎļþ¡£

½ØÖÁ±¾²¼¸æ°ä²¼Ö®ÈÕ£¬ÉÐÎÞ½¨¸´·¨Ê½¡£


CVE-2020-2134, CVE-2020-2135 Script Security Plugin ɳºÐÈÆ¹ý

Äܹ»Í¨¹ýÒÔÏ·½Ê½À´¶ã±ÜScript Security Plugin 1.70ºÍ¸üÔç°æ±¾ÖеÄɳºÐ± £»¤£º

¾«ÐÄ»ú¹ØµÄ»ú¹Øº¯ÊýŲÓúÍÖ÷Ì壨ÓÉÓÚSECURITY-582µÄ²»ÆëÈ«½¨¸´£©

¾«ÐÄÉè¼ÆµÄ²½ÖèŲÓÃʵÏÖGroovyInterceptableµÄ¶ÔÏó

Õâʹ¹¥»÷Õß¿ÉÄÜÔÚJenkinsÖ÷JVMµÄ¸ßµÍÎÄÖÐÖ¸¶¨²¢ÔËÐÐɳºÐ½ÅÕý±¾Ö´ÐÐËÁÒâ´úÂë¡£


Script Security Plugin 1.71ÓµÓÐÆäËûÏ޶Ⱥͽ¡È«ÐԲ鳭£¬ÒÔÈ·±£ÔÚûÓб»É³ÏäÀ¹½ØµÄÇé¿öÏÂÎÞ·¨»ú¹Ø³¬µÈ»ú¹Øº¯Êý¡£´Ë±í£¬Ëü»¹À¹½Ø¶ÔʵÏÖGroovyInterceptableµÄ¶ÔÏóµÄ²½ÖèŲÓã¬×÷Ϊ¶ÔGroovyObject££invokeMethod£¨String£¬Object£©µÄŲÓ㬸öÔÏóÊÇÁÐÈëºÚÃûµ¥µÄ²½Öè¡£


·ì϶ÑéÖ¤


ÔÝÎÞPoC/EXP¡£


½¨¸´½¨Òé


Ŀǰ²¿ÃŲå¼þÒѸüУ¬»ñÈ¡Á´½Ó£ºhttps://jenkins.io/security/advisory/2020-03-09/¡£Çëʵʱ¸üвå¼þµ½Èçϰ汾£º

CryptoMove Plugin ÔÝÎÞ²¹¶¡

Literate Plugin ÔÝÎÞ²¹¶¡

Cobertura Plugin Éý¼¶µ½ 1.16°æ±¾

Rundeck Plugin Éý¼¶µ½ 3.6.7°æ±¾

Script Security Plugin Éý¼¶µ½ 1.71°æ±¾


²Î¿¼Á´½Ó


https://jenkins.io/security/advisory/2020-03-09/