Jenkins Plugins ¶à¸ö°²È«·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-03-11

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-2159 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2138 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2144 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2158 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2134 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2135 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


CryptoMove Plugin 0.1.33ºÍ¸üÔç°æ±¾

Cobertura Plugin 1.15ºÍ¸üÔç°æ±¾

Rundeck Plugin 3.6.6ºÍ¸üÔç°æ±¾

Literate Plugin 1.0ºÍ¸üÔçµÄ°æ±¾

Script Security Plugin 1.70ºÍ¸üÔç°æ±¾


·ì϶¸ÅÊö


CloudBees Jenkins£¨Hudson Labs£©ÊÇÃÀ¹úCloudBees¹«Ë¾µÄÒ»Ì×»ùÓÚJava¿ª·¢µÄ³ÖÐø¼¯³É¹¤¾ß¡£¸Ã²úÆ·ÖØÒªÓÃÓÚ¼à¿Ø³ÖÐøµÄÈí¼þ°æ±¾°ä²¼/²âÊÔÏîÄ¿ºÍһЩ°´Ê±Ö´ÐеŤ×÷¡£


½üÈÕ £¬Jenkins°ä²¼¹Ù·½°²È«¹«¸æ £¬Jenkins²¿ÃŲå¼þ´æÔÚ¶à¸ö·ì϶ £¬ÆäÖиßΣ·ì϶¸ÅÊöÈçÏ£º


CVE-2020-2159 CryptoMove Plugin ºÅÁî×¢Èë

CryptoMove²å¼þ0.1.33ºÍ¸üÔç°æ±¾ÔÊÐí½«OSºÅÁîµÄÅäÖÃ×÷ΪÆä¹¹½¨²½ÖèÅäÖõÄÒ»²¿ÃÅÖ´ÐС£

¸ÃºÅÁ×÷ΪÔËÐÐJenkinsµÄOSÓû§ÕÊ»§ÔÚJenkinsÖ÷·þÎñÆ÷ÉÏÖ´ÐÐ £¬´Ó¶øÔÊÐíÓµÓÐJob/ConfigureȨÏÞµÄÓû§ÔÚJenkinsÖ÷·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâOSºÅÁî¡£

½ØÖÁ±¾²¼¸æ°ä²¼Ö®Ê± £¬ÉÐÎÞ½¨¸´·¨Ê½¡£


CVE-2020-2138 Cobertura Plugin XXE

Cobertura²å¼þ1.15ºÍ¸üÔç°æ±¾Ã»ÓÐÅäÖÃÆäXML½âÎöÆ÷À´Ô¤·ÀXML±í²¿ÊµÌ壨XXE£©¹¥»÷¡£

ÕâʹÓû§¿ÉÄܽÚÔì¡°°ä²¼Cobertura¸²¸ÇÂʻ㱨¡±¹¹½¨ºó²½ÖèµÄÊäÈëÎļþ £¬ÒÔÈÃJenkins½âÎöÔì×÷µÄÎļþ £¬¸ÃÎļþʹÓÃ±í²¿ÊµÌå´ÓJenkinsÖ÷·þÎñÆ÷»ò·þÎñÆ÷¶ËÒªÇóαÔìÖÐÌáÈ¡°ÂÃØ¡£

Cobertura²å¼þ1.16ΪÆäXML½âÎöÆ÷½ûÓÃÁË±í²¿ÊµÌå½âÎö¡£   

 

CVE-2020-2144 Rundeck Plugin XXE

Rundeck²å¼þ3.6.6ºÍ¸üÔç°æ±¾Ã»ÓÐÅäÖÃÆäXML½âÎöÆ÷À´Ô¤·ÀXML±í²¿ÊµÌ壨XXE£©¹¥»÷¡£

ÕâÔÊÐí¾ßÓÓ×°×ÜÌå/¶ÁÈ¡¡±½Ó¼ûȨÏÞµÄÓû§ÈÃJenkinsʹÓÃXMLÊý¾Ý½âÎö¾­¹ý¾«ÐÄÉè¼ÆµÄHTTPÒªÇó £¬¸ÃXMLÒªÇóʹÓÃ±í²¿ÊµÌå´ÓJenkinsÖ÷·þÎñÆ÷»ò·þÎñÆ÷¶ËÒªÇóαÔìÖÐÌáÈ¡»úÃÜ¡£

Rundeck²å¼þ3.6.7ΪÆäXML½âÎöÆ÷½ûÓÃÁË±í²¿ÊµÌå½âÎö¡£   

 

CVE-2020-2158 Literate Plugin Ô¶³Ì´úÂëÖ´ÐÐ

Literate Plugin 1.0ºÍ¸üÔçµÄ°æ±¾Ã»ÓÐÅäÖÃÆäYAML½âÎöÆ÷À´Ô¤·ÀÊ·ý»¯ËÁÒâÀàÐÍ¡£

Õâµ¼ÖÂÔ¶³Ì´úÂëÖ´Ðзì϶ £¬Óû§Äܹ»ÀûÓø÷ì϶ÏòLiterate PluginµÄ¹¹½¨²½ÖèÌṩYAMLÊäÈëÎļþ¡£

½ØÖÁ±¾²¼¸æ°ä²¼Ö®ÈÕ £¬ÉÐÎÞ½¨¸´·¨Ê½¡£


CVE-2020-2134, CVE-2020-2135 Script Security Plugin ɳºÐÈÆ¹ý

Äܹ»Í¨¹ýÒÔÏ·½Ê½À´¶ã±ÜScript Security Plugin 1.70ºÍ¸üÔç°æ±¾ÖеÄɳºÐ±£»¤£º

¾«ÐÄ»ú¹ØµÄ»ú¹Øº¯ÊýŲÓúÍÖ÷Ì壨ÓÉÓÚSECURITY-582µÄ²»ÆëÈ«½¨¸´£©

¾«ÐÄÉè¼ÆµÄ²½ÖèŲÓÃʵÏÖGroovyInterceptableµÄ¶ÔÏó

Õâʹ¹¥»÷Õß¿ÉÄÜÔÚJenkinsÖ÷JVMµÄ¸ßµÍÎÄÖÐÖ¸¶¨²¢ÔËÐÐɳºÐ½ÅÕý±¾Ö´ÐÐËÁÒâ´úÂë¡£


Script Security Plugin 1.71ÓµÓÐÆäËûÏ޶Ⱥͽ¡È«ÐԲ鳭 £¬ÒÔÈ·±£ÔÚûÓб»É³ÏäÀ¹½ØµÄÇé¿öÏÂÎÞ·¨»ú¹Ø³¬µÈ»ú¹Øº¯Êý¡£´Ë±í £¬Ëü»¹À¹½Ø¶ÔʵÏÖGroovyInterceptableµÄ¶ÔÏóµÄ²½ÖèŲÓà £¬×÷Ϊ¶ÔGroovyObject££invokeMethod£¨String £¬Object£©µÄŲÓà £¬¸Ã¶ÔÏóÊÇÁÐÈëºÚÃûµ¥µÄ²½Öè¡£


·ì϶ÑéÖ¤


ÔÝÎÞPoC/EXP¡£


½¨¸´½¨Òé


Ŀǰ²¿ÃŲå¼þÒѸüР£¬»ñÈ¡Á´½Ó£ºhttps://jenkins.io/security/advisory/2020-03-09/¡£Çëʵʱ¸üвå¼þµ½Èçϰ汾£º

CryptoMove Plugin ÔÝÎÞ²¹¶¡

Literate Plugin ÔÝÎÞ²¹¶¡

Cobertura Plugin Éý¼¶µ½ 1.16°æ±¾

Rundeck Plugin Éý¼¶µ½ 3.6.7°æ±¾

Script Security Plugin Éý¼¶µ½ 1.71°æ±¾


²Î¿¼Á´½Ó


https://jenkins.io/security/advisory/2020-03-09/