Jenkins | ²å¼þ¶à¸ö°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-05-08

0x00 ·ì϶¸ÅÊö



²úÆ·

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Ó°ÏìÁìÓò

Jenkins²å¼þ

CVE-2020-2181

IPC

ÖÐΣ

ÊÇ

Amazon EC2 Plugin <= 1.50.1

Copy Artifact Plugin <= 1.43.1

Credentials Binding Plugin <= 1.22

CVS Plugin <= 2.15

SCM Filter Jervis Plugin <= 0.2.1

CVE-2020-2182

IPC

ÖÐΣ

ÊÇ

CVE-2020-2183

IA

ÖÐΣ

ÊÇ

CVE-2020-2184

CSRF

ÖÐΣ

ÊÇ

CVE-2020-2185

IVE

µÍΣ

ÊÇ

CVE-2020-2186

CSRF

ÖÐΣ

ÊÇ

CVE-2020-2187

IVE

¸ßΣ

ÊÇ

CVE-2020-2188

IA

µÍΣ

ÊÇ

CVE-2020-2189

RCE

ÖÐΣ

ÊÇ


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



CloudBees Jenkins£¨Hudson Labs£©ÊÇÃÀ¹úCloudBees¹«Ë¾µÄÒ»Ì×»ùÓÚJava¿ª·¢µÄ³ÖÐø¼¯³É¹¤¾ß¡£¸Ã²úÆ·ÖØÒªÓÃÓÚ¼à¿Ø³ÖÐøµÄÈí¼þ°æ±¾°ä²¼/²âÊÔÏîÄ¿ºÍһЩ°´Ê±Ö´ÐеŤ×÷¡£

2020Äê5ÔÂ6ÈÕ£¬Jenkins¹Ù·½°ä²¼°²È«²¼¸æ½¨¸´²å¼þÖеÄ9¸ö·ì϶£¬ÆäÖÐÓÐ5¸ö²å¼þÊܵ½Ó°Ïì¡£¾ßÌåÄÚÈÝÈçÏ£º

Credentials Binding ²å¼þ´æÔÚÁ½¸öÍ´´¦Ð¹Â¶·ì϶£¨CVE-2020-2181¡¢CVE-2020-2182£©£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñÈ¡Ãô¸ÐÐÅÏ¢¡£

Copy Artifact ²å¼þ´æÔÚȨÏÞУÑé²»µ±·ì϶£¨CVE-2020-2183£©£¬¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úÆ·ÖжÌȱÉí·ÝÑéÖ¤´ëÊ©»òÉí·ÝÑé֤ǿ¶È²»¼°¡£

CVS ²å¼þ´æÔÚ¿çÕ¾ÒªÇóαÔì·ì϶£¨CVE-2020-2184£©£¬¸Ã·ì϶ԴÓÚWEBÀûÓÃδ³ä·ÖÑéÖ¤ÒªÇóÊÇ·ñÀ´×Ô¿ÉÐÅÓþ»§¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ͨ¹ýÊÜÓ°Ïì¿Í»§¶ËÏò·þÎñÆ÷·¢ËÍ·ÇÔ¤ÆÚµÄÒªÇó¡£

Amazon EC2 ²å¼þ´æÔÚ4 ¸ö·ì϶£¨CVE-2020-2185¡¢CVE-2020-2186¡¢CVE-2020-2187¡¢CVE-2020-2188£©¡£CVE-2020-2185Ô´ÓÚ²»×ã¶ÔSSHÖ÷»úÃÜÔ¿µÄÑéÖ¤¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐÖÐÑëÈ˹¥»÷¡£CVE-2020-2186Ô´ÓÚWEBÀûÓÃδ³ä·ÖÑéÖ¤ÒªÇóÊÇ·ñÀ´×Ô¿ÉÐÅÓþ»§¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ͨ¹ýÊÜÓ°Ïì¿Í»§¶ËÏò·þÎñÆ÷·¢ËÍ·ÇÔ¤ÆÚµÄÒªÇó¡£CVE-2020-2187Ô´ÓÚ·¨Ê½Ã»ÓÐÑéÖ¤SSL/TLSÖ¤ÊéºÍÖ÷»úÃû¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐÖÐÑëÈ˹¥»÷¡£CVE-2020-2188Ô´ÓÚÍøÂçϵͳ»ò²úÆ·ÖжÌȱÉí·ÝÑéÖ¤´ëÊ©»òÉí·ÝÑé֤ǿ¶È²»¼°¡£

SCM Filter Jervis²å¼þ´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-2189£©£¬¸Ã·ì϶ԴÓÚSCM Filter Jervis²å¼þĬÈϲ»ÅäÖÃYAML½âÎöÆ÷£¬µ¼ÖÂÓû§Äܹ»Ê¹ÓùýÂËÆ÷ÅäÖÃÏîÄ¿£¬Ò²Äܹ»²Ù×÷SCMÒÑ´æ´¢ÅäÖùýµÄÏîÄ¿ÄÚÈÝ¡£


0x02 ·ì϶¼ì²â


½¨ÒéÓйØÓû§¾¡¿ì²é¿´µ±Ç°Ê¹ÓõIJå¼þ°æ±¾£¬È·ÈÏÊÇ·ñÔÚÊÜÓ°ÏìÁìÓòÄÚ£¬²¢ÊµÊ±Éý¼¶ÖÁ°²È«°æ±¾½øÐзÀ»¤£¬²Ù×÷²½ÖèÈçÏ£º

µã»÷¡°Manage Jenkins¡±½øÈëÖÎÀíÄ£¿é£¬Ñ¡Ôñ¡°Manage Plugins¡±ÖÎÀí²å¼þ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



µã»÷¡°installed¡±¼´¿É¶Ôµ±Ç°ÒÑ×°ÖõIJå¼þ°æ±¾½øÐв鿴¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



0x03 ´ëÖý¨Òé


ĿǰJenkins¹Ù·½ÒѾ­Õë¶ÔÕâ´Î·ì϶°ä²¼ÁËеIJå¼þ°æ±¾£¬ÇëÓйØÓû§¾¡¿ìÉý¼¶ÊÜÓ°ÏìµÄ²å¼þÖÁ°²È«°æ±¾£¬²Ù×÷²½ÖèÈçÏ£º

ÔÚ²å¼þÖÎÀí½çÃæÑ¡Ôñ±ØÒªÉý¼¶µÄ²å¼þ£¬µã»÷¡°Download now and install after restart¡±½øÐиüвÙ×÷¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



0x04 ÓйØÐÂÎÅ


https://www.openwall.com/lists/oss-security/2020/05/06/3


0x05 ²Î¿¼Á´½Ó


https://www.jenkins.io/security/advisory/2020-05-06/


0x06 ¹¦·òÏß


2020-05-06  Jenkins¹Ù·½°ä²¼²¼¸æ

2020-05-08 VSRC°ä²¼·ì϶¹«¸æ




GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾