Jenkins½¨¸´¶à¸ö°²È«·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-07-25
·ì϶±àºÅºÍ¼¶±ð
CVE-2018-1999001  ³§ÉÌ×ÔÆÀ£º¸ß  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999002  ³§ÉÌ×ÔÆÀ£º¸ß  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999003  ³§ÉÌ×ÔÆÀ£ºÖР CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999004  ³§ÉÌ×ÔÆÀ£ºÖР CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999005  ³§ÉÌ×ÔÆÀ£ºÖР CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999006  ³§ÉÌ×ÔÆÀ£ºÖР CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE-2018-1999007  ³§ÉÌ×ÔÆÀ£ºÖР CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾

Jenkins weekly 2.132 ÒÔ¼°¸üÔçµÄ°æ±¾

Jenkins LTS 2.121.1 ÒÔ¼°¸üÔçµÄ°æ±¾


·ì϶¸ÅÊö
JenkinsÊÇÒ»¸ö¿ªÔ´Èí¼þÏîÄ¿£¬ÊÇ»ùÓÚJava¿ª·¢µÄÒ»ÖÖ³ÖÐø¼¯³É¹¤¾ß£¬ÓÃÓÚ¼à¿Ø³ÖÐø³Á¸´µÄ¹¤×÷£¬Ö¼ÔÚÌṩһ¸öÊ¢¿ªÒ×ÓõÄÈí¼þƽ̨£¬Ê¹Èí¼þµÄ³ÖÐø¼¯³ÉÔì³É¿ÉÄÜ¡£

Jenkins ¹Ù·½ÔÚ 7 Ô 18 ºÅ°ä²¼Á˰²È«×ÊѶ£¬¶ÔÁ½¸ö¸ßΣºÍ5¸öÖм¶·ì϶½øÐй«¸æ£º https://jenkins.io/security/advisory/2018-07-18/¡£


CVE-2018-1999001ÅäÖÃÎļþõ辶Ťתµ¼ÖÂÖÎÀíԱȨÏÞÊ¢¿ª·ì϶
Ô¶³ÌÇÒδ¾­ÊÚȨµÄ¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâµÇ¼ƾ֤£¬´ÓJenkins Ö÷Ŀ¼ÏÂÒÆ³ý config.xml ÅäÖÃÎļþµ½ÆäËûĿ¼£¬´Ó¶øµ¼Ö Jenkins ·þÎñÏ´γÁÆôʱÍË»Ø legacy ģʽ£¬¶ÔÄäÃûÓû§Ò²»áÊ¢¿ªÖÎÀíԱȨÏÞ£¬ÈçÏÂͼËùʾ£º

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´Ë·ì϶ÀûÓõÄǰÌáÊDZØÒªÆÚ´ý Jenkins ·þÎñµÄ³ÁÆô¡£


ΪÁË»º½â´ËÎÊÌ⣬ÎÒÃÇÇ¿ÁÒ½¨ÒéûÓд˽¨¸´·¨Ê½µÄJenkinsÊ·ýµÄÖÎÀíÔ±Äܹ»Óɲ»ÊÜÐÅÀµµÄÓû§½Ó¼û£¬ÔڹعØJenkins֮ǰ²»¾Ã±£ÁôÈ«¾ÖÅäÖá£ÕâÑù×ö»á½«µ±Ç°ÅäÖôÓÄÚ´æÐ´Èëconfig.xmlÎļþ£¬¸ÃÎļþ½öÔÚÆô¶¯Ê±»ò³ÁмÓÔØÅäÖÃʱ¶ÁÈ¡¡£

ÈôÊÇÔÚÀûÓôËÎÊÌâºóJenkinsÒѾ­¹Ø¹Ø£¬ÔòÄܹ»ÔÚJenkinsÖ÷Ŀ¼ÖеÄusers/$002e$002e/config.xmlÖÐÕÒµ½config.xmlÎļþ¡£


CVE-2018-1999002ËÁÒâÎļþ¶ÁÈ¡·ì϶

Jenkins ʹÓÃµÄ Stapler Web ¿ò¼Ü´æÔÚËÁÒâÎļþ¶ÁÈ¡·ì϶¡£¹¥»÷ÕßÔÚÔ¶³ÌÇÒδ¾­ÊÚȨµÄÇé¿öÏ£¬Äܹ»Í¨¹ý»ú¹Ø¶ñÒâµÄ HTTP ÒªÇó·¢Íù Jenkins Web ·þÎñ¶Ë£¬´ÓÒªÇóÏìÓ¦ÖÐÖ±½Ó»ñÈ¡¹¥»÷ÕßÖ¸¶¨¶ÁÈ¡µÄÎļþÄÚÈÝ¡£


´Ó¹Ù·½Ìá½»µÄ°²È«²âÊÔ²¹¶¡ÖУ¬Äܹ»¿´³ö£¬´Ë·ì϶ÊÇÔÚ HTTP ÒªÇóÍ· Accept-Language ÖнøÐжñÒâÊý¾Ý»ú¹Ø£¬²¢ÖØÒªÕë¶Ô Windows ϵͳ£¨ÔÚ Linux ϵͳÉÏÀûÓÃÔò±ØÒªÂú×ãÌØ¶¨Ç°Ìᣩ£º

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


²âÊÔ·¢ÏÖ´Ë·ì϶µÄÀûÓñØÒª¿ªÆôÄäÃûÓû§½Ó¼ûȨÏÞ£¨²âÊ԰汾Ϊ Jenkins LTS 2.121.1£©¡£

StaplerÖеÄÊäÈëÑéÖ¤Òѵõ½¸Ä½ø£¬ÒÔÔ¤·ÀÕâÖÖÇé¿ö²úÉú¡£


CVE-2018-1999003δ¾­ÊÚȨµÄÓû§Äܹ»È¡µÞÁжӵĹ¹½¨
´¦ÖÃÁжӹ¹½¨È¡µÞµÄURLδִÐÐȨÏ޲鳭£¬ÔÊÐí¾ßÓÓ×°×ÜÌå/¶ÁÈ¡¡±È¨ÏÞµÄÓû§È¡µÞÁжӹ¹½¨¡£

´¦ÖÃÁжӹ¹½¨µÄÈ¡µÞµÄURL´Ë¿ÌÈ·±£Óû§ÓµÓÐÏîÄ¿/È¡µÞȨÏÞ¡£


CVE-2018-1999004δ¾­ÊÚȨµÄÓû§Äܹ»Æô¶¯ºÍ¶ôÖÆ´úÀíÆô¶¯
ÔÚJenkinsÖ÷·þÎñÆ÷ÉÏÆô¶¯´úÀíÆô¶¯µÄURLδִÐÐȨÏ޲鳭£¬ÔÊÐí¾ßÓÓ×°×ÜÌå/¶ÁÈ¡¡±È¨ÏÞµÄÓû§Æô¶¯´úÀíÆô¶¯¡£
ÕâÑù×öÈ¡µÞÁËÖ¸¶¨´úÀí·¨Ê½µÄËùÓÐÔÚ½øÐÐµÄÆô¶¯£¬Òò¶øÕâÔÊÐí¹¥»÷Õß×èÖ¹´úÀíÎÞÆÚÏÞÆô¶¯¡£

´Ë¿Ì£¬´úÀíÆô¶¯µÄURL¿ÉÈ·±£Óû§¾ßÓÓ×°´úÀí/Ïνӡ±È¨ÏÞ¡£


CVE-2018-1999005´æ´¢µÄXSS·ì϶
ÔÚÏñ/ view / ... / buildsÕâÑùµÄURLÉÏÏÔʾµÄ¹¹½¨¹¦·òÏßÓײ¿¼þûÓÐÕýÈ·µØ×ªÒåÏîÖ÷ÕÅÏÔʾÃû³Æ¡£Õâµ¼ÖÂÁË¿ÉÄܽÚÔìÏîÄ¿ÏÔʾÃû³ÆµÄÓû§¿ÉÀûÓõĿçÕ¾µã¾ç±¾·ì϶¡£

Jenkins´Ë¿ÌתÒ幦·òÏßÓײ¿¼þÉÏÏÔʾµÄ×÷ÒµÏÔʾÃû³Æ¡£


CVE-2018-1999006δ¾­ÊÚȨµÄÓû§Äܹ»È·¶¨ºÎʱ´ÓÆäJPI°üÖÐÌáÈ¡²å¼þ
ÅúʾºÎʱ½«²å¼þJPIÎļþ×îºóÌáÈ¡µ½JenkinsÖ÷Ŀ¼ÖеIJå¼þ/×ÓĿ¼ÖеÄÎļþ¿ÉÓÉÓµÓÐ×ÜÌå/¶ÁȡȨÏÞµÄÓû§Í¨¹ýHTTP½Ó¼û¡£ÕâÔÊÐíδ¾­ÊÚȨµÄÓû§È·¶¨¸ø¶¨²å¼þµÄ¿ÉÄÜ×°ÖÃÈÕÆÚ¡£

ÊÜÓ°ÏìµÄÎļþ²»ÔÙͨ¹ýHTTPÌṩ¡£


CVE-2018-1999007 Staplerµ÷ÊÔģʽϵÄXSS·ì϶
StaplerÊÇJenkinsÓÃÓÚ·ÓÉHTTPÒªÇóµÄWeb¿ò¼Ü¡£ÆôÓÃÆäµ÷ÊÔģʽºó£¬HTTP 404ÃýÎóÒ³Ãæ½«ÏÔʾÕï¶ÏÐÅÏ¢¡£ÕâЩÃýÎóÒ³ÃæÃ»ÓÐÌÓ±ÜËüÃÇÏÔʾµÄ²¿ÃÅURL£¬ÔÚ¼«ÉÙÊýÇé¿öÏ»ᵼÖ¿çÕ¾µã¾ç±¾·ì϶¡£
´Ë¿ÌÄܹ»ÕýȷתÒåÕâЩÃýÎóÒ³ÃæÉÏÏÔʾµÄ²¿ÃÅURL¡£

×÷Ϊ½â¾ö²½Ö裬²»Ó¦ÔÚStaplerµ÷ÊÔģʽ϶Բ»ÊÜÐÅÀµµÄÓû§¿É½Ó¼ûµÄÊ·ýÆôÓÃStaplerµ÷ÊÔģʽ¡£


½¨¸´½¨Ò飺
Óû§Ó¦ÊµÊ±Éý¼¶½øÐзÀ»¤£º
Jenkins weekly Éý¼¶µ½ 2.133 °æ±¾

Jenkins LTS Éý¼¶µ½ 2.121.2 °æ±¾


²Î¿¼Á´½Ó£º
https://jenkins.io/security/advisory/2018-07-18/
https://github.com/jenkinsci/jenkins/commit/d71ac6ffe98ee62e0353af7a948a4ae1a69b67e9