Jenkins Plugins ¶à¸ö°²È«·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-02-14·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-2116£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-2117£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-2109£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-2110£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-2121£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-2123£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-2120£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-2115£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Applatix Plugin <= 1.1£¬Azure AD Plugin <= 1.1.2£¬BMC Release Package and Deployment Plugin <= 1.1£¬Brakeman Plugin <= 0.12£¬Debian Package Builder Plugin <= 1.6.11£¬DigitalOcean Plugin <= 1.1£¬Dynamic Extended Choice Parameter Plugin <= 1.0.1£¬Eagle Tester Plugin <= 1.0.9£¬ECX Copy Data Management Plugin <= 1.9£¬FitNesse Plugin <= 1.30£¬Git Parameter Plugin <= 0.9.11£¬Google Kubernetes Engine Plugin <= 0.8.0£¬Harvest SCM Plugin <= 0.5.1£¬NUnit Plugin <= 0.25£¬Parasoft Environment Manager Plugin <= 2.14£¬Pipeline GitHub Notify Step Plugin <= 1.0.4£¬Pipeline: Groovy Plugin <= 2.78£¬RadarGun Plugin <= 1.7£¬S3 publisher Plugin <= 0.11.4£¬Script Security Plugin <= 1.69£¬Subversion Plugin <= 2.13.0
·ì϶¸ÅÊö
CloudBees Jenkins£¨Hudson Labs£©ÊÇÃÀ¹úCloudBees¹«Ë¾µÄÒ»Ì×»ùÓÚJava¿ª·¢µÄ³ÖÐø¼¯³É¹¤¾ß¡£¸Ã²úÆ·ÖØÒªÓÃÓÚ¼à¿Ø³ÖÐøµÄÈí¼þ°æ±¾°ä²¼/²âÊÔÏîÄ¿ºÍһЩ°´Ê±Ö´ÐеŤ×÷¡£
½üÈÕ£¬Jenkins°ä²¼¹Ù·½°²È«¹«¸æ£¬Jenkins²¿ÃŲå¼þ´æÔÚ¶à¸ö·ì϶£¬Éæ¼°µ½Èçϰ²È«ÎÊÌ⣺ɳÏäÈÆ¹ý£¬XSS·ì϶£¬´¿Îı¾Ìåʽ´«Ê䣬XXE£¬CSRF£¬¶ÌȱȨÏ޲鳣¬Ã¶¾ÙÍ´´¦ID£¬RCE£¬XSS£¬´¿Îı¾Ìåʽ´æ´¢ÃÜÂ룬ÆäÖиßΣ·ì϶¸ÅÊöÈçÏ£º
Pipeline GitHub Notify Step²å¼þÖеÄCSRF·ì϶ºÍ¶ÌȱȨÏÞ²é³ÔÊÐí²¶»ñÍ´´¦£¬CVE-2020-2116 (CSRF)/CVE-2020-2117(¶ÌȱȨÏÞ²é³)
Pipeline GitHub Notify Step Plugin 1.0.4ºÍ¸üÔç°æ±¾²»ºÏʵÏÖ±íµ¥ÑéÖ¤µÄ²½ÖèÖ´ÐÐȨÏ޲鳡£ÕâÔÊÐí¶ÔJenkinsÓµÓÐÈ«Ãæ/¶ÁÈ¡½Ó¼ûȨÏÞµÄÓû§Ê¹ÓÃͨ¹ýÁíÒ»ÖÖ²½Öè»ñµÃµÄ¹¥»÷ÕßÖ¸¶¨µÄÍ´´¦idÏνӵ½¹¥»÷ÕßÖ¸¶¨µÄURL£¬´Ó¶ø²¶»ñJenkinsÖд洢µÄÍ´´¦¡£
´Ë±í£¬±íµ¥ÑéÖ¤²½Öè²»±ØÒªPOSTÒªÇ󣬴Ӷøµ¼ÖÂCSRF·ì϶¡£
ͨ¹ý¹Ü·ÖеÄĬÈϲ½Öè²ÎÊý±í°×Ê½ÈÆ¹ýɳºÐ£ºGroovy²å¼þ£¬CVE-2020-2109
¹Ü·ÖеÄɳºÐ±£»¤£ºGroovy²å¼þ2.78¼°¸üÔç°æ±¾Äܹ»Í¨¹ýCPSת»»²½ÖèÖеÄĬÈϲÎÊý±í°×ʽÀ´¶ã±Ü¡£ÕâʹµÃ¹¥»÷Õß¿ÉÄÜÖ¸¶¨²¢ÔËÐÐɳºÐ¹Ü·£¬ÒÔ±ãÔÚJenkinsÖ÷JVMµÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£
Script Security²å¼þÖеÄɳºÐÈÆ¹ý·ì϶£¬CVE-2020-2110
Script Security²å¼þ1.69¼°¸üÔç°æ±¾ÖеÄɳºÐ±£»¤Äܹ»Ôھ籾±àÒë½×¶Îͨ¹ý½«ASTת»»×¢½â£¨Èç@Grab£©ÀûÓÃÓÚµ¼Èë»òÔÚÆäËû×¢½âÖÐʹÓÃËüÃÇÀ´¶ã±Ü¡£Õâ»áÓ°Ïì¾ç±¾Ö´ÐУ¨Í¨³£´ÓÆäËû²å¼þ£¨Èç¹Ü·£©Å²Óã©ÒÔ¼°ÌṩɳºÐ¾ç±¾ÑéÖ¤µÄHTTP¶Ëµã¡£
ÓµÓÐÈ«¾Ö/¶ÁȡȨÏÞµÄÓû§Äܹ»ÀûÓô˷ìÏ¶ÈÆ¹ýɳºÐ±£»¤£¬²¢ÔÚJenkinsÖ÷»úÉÏÖ´ÐÐËÁÒâ´úÂë¡£
Google Kubernetes Engine²å¼þÖеÄRCE·ì϶£¬CVE-2020-2121
Google Kubernetes Engine²å¼þ0.8.0ºÍ¸üÔç°æ±¾Ã»ÓÐÅäÖÃÆäYAML½âÎöÆ÷À´Ô¤·ÀËÁÒâÀàÐ͵ÄÊ·ý»¯¡£Õâµ¼ÖÂÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¬Óû§Äܹ»ÀûÓø÷ì϶ÏòGoogle Kubernetes Engine²å¼þµÄ¹¹½¨²½ÖèÌṩYAMLÊäÈëÎļþ¡£
RadarGun²å¼þÖеÄRCE·ì϶£¬CVE-2020-2123
RadarGun²å¼þ1.7¼°¸üÔç°æ±¾Ã»ÓÐÅäÖÃÆäYAML½âÎöÆ÷ÒÔÔ¤·ÀËÁÒâÀàÐ͵ÄÊ·ý»¯¡£Õâ»áµ¼ÖÂÔ¶³Ì´úÂëÖ´Ðзì϶±»¿ÉÄÜÅäÖÃRadarGun²å¼þµÄÌìÉú²½ÖèµÄÓû§ÀûÓá£
FitNesse²å¼þÖеÄXXE·ì϶£¬CVE-2020-2120
FitNesse²å¼þ1.30¼°¸üÔç°æ±¾Ã»ÓÐÅäÖÃXML½âÎöÆ÷ÒÔÔ¤·ÀXML±í²¿ÊµÌ壨XXE£©¹¥»÷¡£
ÕâÔÊÐíÓû§½ÚÔìÆäºóÆÚÌìÉú²½ÖèµÄÊäÈëÎļþ£¬ÈÃJenkins½âÎöÒ»¸ö¾«ÐļÙÔìµÄÎļþ£¬¸ÃÎļþʹÓÃ±í²¿ÊµÌå´ÓJenkinsÖ÷»úÌáÈ¡»úÃÜ¡¢·þÎñÆ÷¶ËÒªÇóαÔì»ò»Ø¾ø·þÎñ¹¥»÷¡£
NUnit²å¼þÖеÄXXE·ì϶£¬CVE-2020-2115
NUnit²å¼þ0.25¼°¸üÔç°æ±¾Ã»ÓÐÅäÖÃXML½âÎöÆ÷ÒÔÔ¤·ÀXML±í²¿ÊµÌ壨XXE£©¹¥»÷¡£
ÕâÔÊÐíÓû§½ÚÔìÆäºóÆÚÌìÉú²½ÖèµÄÊäÈëÎļþ£¬ÈÃJenkins½âÎöÒ»¸ö¾«ÐļÙÔìµÄÎļþ£¬¸ÃÎļþʹÓÃ±í²¿ÊµÌå´ÓJenkinsÖ÷»úÌáÈ¡»úÃÜ¡¢·þÎñÆ÷¶ËÒªÇóαÔì»ò»Ø¾ø·þÎñ¹¥»÷¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
Ŀǰ²¿ÃŲå¼þÒѸüУ¬»ñÈ¡Á´½Ó£ºhttps://jenkins.io/security/advisory/2020-02-12/¡£Çëʵʱ¸üвå¼þµ½Èçϰ汾£º
Azure AD Plugin ¸üÐÂÖÁ 1.2.0
Brakeman Plugin ¸üÐÂÖÁ 0.13
FitNesse Plugin ¸üÐÂÖÁ 1.31
Git Parameter Plugin ¸üÐÂÖÁ 0.9.12
Google Kubernetes Engine Plugin ¸üÐÂÖÁ 0.8.1
NUnit Plugin ¸üÐÂÖÁ 0.26
Pipeline GitHub Notify Step Plugin ¸üÐÂÖÁ 1.0.5
Pipeline: Groovy Plugin ¸üÐÂÖÁ 2.79
RadarGun Plugin ¸üÐÂÖÁ 1.8
S3 publisher Plugin ¸üÐÂÖÁ 0.11.5
Script Security Plugin ¸üÐÂÖÁ 1.70
Subversion Plugin ¸üÐÂÖÁ 2.13.1
ÒÔϲå¼þÔÝ佨¸´£º
Applatix Plugin
BMC Release Package and Deployment Plugin
Debian Package Builder Plugin
DigitalOcean Plugin
Dynamic Extended Choice Parameter Plugin
Eagle Tester Plugin
ECX Copy Data Management Plugin
Harvest SCM Plugin
Parasoft Environment Manager Plugin
²Î¿¼Á´½Ó
https://jenkins.io/security/advisory/2020-02-12/


¾©¹«Íø°²±¸11010802024551ºÅ