Jenkins½¨¸´¶à¸ö°²È«·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-07-25CVE-2018-1999001 ³§ÉÌ×ÔÆÀ£º¸ß CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999002 ³§ÉÌ×ÔÆÀ£º¸ß CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999003 ³§ÉÌ×ÔÆÀ£ºÖÐ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999004 ³§ÉÌ×ÔÆÀ£ºÖÐ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999005 ³§ÉÌ×ÔÆÀ£ºÖÐ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999006 ³§ÉÌ×ÔÆÀ£ºÖÐ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999007 ³§ÉÌ×ÔÆÀ£ºÖÐ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Jenkins weekly 2.132 ÒÔ¼°¸üÔçµÄ°æ±¾Jenkins LTS 2.121.1 ÒÔ¼°¸üÔçµÄ°æ±¾
JenkinsÊÇÒ»¸ö¿ªÔ´Èí¼þÏîÄ¿£¬ÊÇ»ùÓÚJava¿ª·¢µÄÒ»ÖÖ³ÖÐø¼¯³É¹¤¾ß£¬ÓÃÓÚ¼à¿Ø³ÖÐø³Á¸´µÄ¹¤×÷£¬Ö¼ÔÚÌṩһ¸öÊ¢¿ªÒ×ÓõÄÈí¼þƽ̨£¬Ê¹Èí¼þµÄ³ÖÐø¼¯³ÉÔì³É¿ÉÄÜ¡£
Jenkins ¹Ù·½ÔÚ 7 Ô 18 ºÅ°ä²¼Á˰²È«×ÊѶ£¬¶ÔÁ½¸ö¸ßΣºÍ5¸öÖм¶·ì϶½øÐй«¸æ£º https://jenkins.io/security/advisory/2018-07-18/¡£
Ô¶³ÌÇÒδ¾ÊÚȨµÄ¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâµÇ¼ƾ֤£¬´ÓJenkins Ö÷Ŀ¼ÏÂÒÆ³ý config.xml ÅäÖÃÎļþµ½ÆäËûĿ¼£¬´Ó¶øµ¼Ö Jenkins ·þÎñÏ´γÁÆôʱÍË»Ø legacy ģʽ£¬¶ÔÄäÃûÓû§Ò²»áÊ¢¿ªÖÎÀíԱȨÏÞ£¬ÈçÏÂͼËùʾ£º
´Ë·ì϶ÀûÓõÄǰÌáÊDZØÒªÆÚ´ý Jenkins ·þÎñµÄ³ÁÆô¡£
ÈôÊÇÔÚÀûÓôËÎÊÌâºóJenkinsÒѾ¹Ø¹Ø£¬ÔòÄܹ»ÔÚJenkinsÖ÷Ŀ¼ÖеÄusers/$002e$002e/config.xmlÖÐÕÒµ½config.xmlÎļþ¡£
Jenkins ʹÓÃµÄ Stapler Web ¿ò¼Ü´æÔÚËÁÒâÎļþ¶ÁÈ¡·ì϶¡£¹¥»÷ÕßÔÚÔ¶³ÌÇÒδ¾ÊÚȨµÄÇé¿öÏ£¬Äܹ»Í¨¹ý»ú¹Ø¶ñÒâµÄ HTTP ÒªÇó·¢Íù Jenkins Web ·þÎñ¶Ë£¬´ÓÒªÇóÏìÓ¦ÖÐÖ±½Ó»ñÈ¡¹¥»÷ÕßÖ¸¶¨¶ÁÈ¡µÄÎļþÄÚÈÝ¡£
²âÊÔ·¢ÏÖ´Ë·ì϶µÄÀûÓñØÒª¿ªÆôÄäÃûÓû§½Ó¼ûȨÏÞ£¨²âÊ԰汾Ϊ Jenkins LTS 2.121.1£©¡£
StaplerÖеÄÊäÈëÑéÖ¤Òѵõ½¸Ä½ø£¬ÒÔÔ¤·ÀÕâÖÖÇé¿ö²úÉú¡£
´¦ÖÃÁжӹ¹½¨È¡µÞµÄURLδִÐÐȨÏ޲鳣¬ÔÊÐí¾ßÓÓ×°×ÜÌå/¶ÁÈ¡¡±È¨ÏÞµÄÓû§È¡µÞÁжӹ¹½¨¡£
´¦ÖÃÁжӹ¹½¨µÄÈ¡µÞµÄURL´Ë¿ÌÈ·±£Óû§ÓµÓÐÏîÄ¿/È¡µÞȨÏÞ¡£
ÔÚJenkinsÖ÷·þÎñÆ÷ÉÏÆô¶¯´úÀíÆô¶¯µÄURLδִÐÐȨÏ޲鳣¬ÔÊÐí¾ßÓÓ×°×ÜÌå/¶ÁÈ¡¡±È¨ÏÞµÄÓû§Æô¶¯´úÀíÆô¶¯¡£
ÕâÑù×öÈ¡µÞÁËÖ¸¶¨´úÀí·¨Ê½µÄËùÓÐÔÚ½øÐÐµÄÆô¶¯£¬Òò¶øÕâÔÊÐí¹¥»÷Õß×èÖ¹´úÀíÎÞÆÚÏÞÆô¶¯¡£
´Ë¿Ì£¬´úÀíÆô¶¯µÄURL¿ÉÈ·±£Óû§¾ßÓÓ×°´úÀí/Ïνӡ±È¨ÏÞ¡£
ÔÚÏñ/ view / ... / buildsÕâÑùµÄURLÉÏÏÔʾµÄ¹¹½¨¹¦·òÏßÓײ¿¼þûÓÐÕýÈ·µØ×ªÒåÏîÖ÷ÕÅÏÔʾÃû³Æ¡£Õâµ¼ÖÂÁË¿ÉÄܽÚÔìÏîÄ¿ÏÔʾÃû³ÆµÄÓû§¿ÉÀûÓõĿçÕ¾µã¾ç±¾·ì϶¡£
Jenkins´Ë¿ÌתÒ幦·òÏßÓײ¿¼þÉÏÏÔʾµÄ×÷ÒµÏÔʾÃû³Æ¡£
ÅúʾºÎʱ½«²å¼þJPIÎļþ×îºóÌáÈ¡µ½JenkinsÖ÷Ŀ¼ÖеIJå¼þ/×ÓĿ¼ÖеÄÎļþ¿ÉÓÉÓµÓÐ×ÜÌå/¶ÁȡȨÏÞµÄÓû§Í¨¹ýHTTP½Ó¼û¡£ÕâÔÊÐíδ¾ÊÚȨµÄÓû§È·¶¨¸ø¶¨²å¼þµÄ¿ÉÄÜ×°ÖÃÈÕÆÚ¡£
ÊÜÓ°ÏìµÄÎļþ²»ÔÙͨ¹ýHTTPÌṩ¡£
StaplerÊÇJenkinsÓÃÓÚ·ÓÉHTTPÒªÇóµÄWeb¿ò¼Ü¡£ÆôÓÃÆäµ÷ÊÔģʽºó£¬HTTP 404ÃýÎóÒ³Ãæ½«ÏÔʾÕï¶ÏÐÅÏ¢¡£ÕâЩÃýÎóÒ³ÃæÃ»ÓÐÌÓ±ÜËüÃÇÏÔʾµÄ²¿ÃÅURL£¬ÔÚ¼«ÉÙÊýÇé¿öÏ»ᵼÖ¿çÕ¾µã¾ç±¾·ì϶¡£
´Ë¿ÌÄܹ»ÕýȷתÒåÕâЩÃýÎóÒ³ÃæÉÏÏÔʾµÄ²¿ÃÅURL¡£
×÷Ϊ½â¾ö²½Ö裬²»Ó¦ÔÚStaplerµ÷ÊÔģʽ϶Բ»ÊÜÐÅÀµµÄÓû§¿É½Ó¼ûµÄÊ·ýÆôÓÃStaplerµ÷ÊÔģʽ¡£
Óû§Ó¦ÊµÊ±Éý¼¶½øÐзÀ»¤£º
Jenkins weekly Éý¼¶µ½ 2.133 °æ±¾
Jenkins LTS Éý¼¶µ½ 2.121.2 °æ±¾
https://jenkins.io/security/advisory/2018-07-18/
https://github.com/jenkinsci/jenkins/commit/d71ac6ffe98ee62e0353af7a948a4ae1a69b67e9


¾©¹«Íø°²±¸11010802024551ºÅ