Jenkins | ²å¼þ¶à¸ö°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-05-08

0x00 ·ì϶¸ÅÊö



²úÆ·

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Ó°ÏìÁìÓò

Jenkins²å¼þ

CVE-2020-2181

IPC

ÖÐΣ

ÊÇ

Amazon EC2 Plugin <= 1.50.1

Copy Artifact Plugin <= 1.43.1

Credentials Binding Plugin <= 1.22

CVS Plugin <= 2.15

SCM Filter Jervis Plugin <= 0.2.1

CVE-2020-2182

IPC

ÖÐΣ

ÊÇ

CVE-2020-2183

IA

ÖÐΣ

ÊÇ

CVE-2020-2184

CSRF

ÖÐΣ

ÊÇ

CVE-2020-2185

IVE

µÍΣ

ÊÇ

CVE-2020-2186

CSRF

ÖÐΣ

ÊÇ

CVE-2020-2187

IVE

¸ßΣ

ÊÇ

CVE-2020-2188

IA

µÍΣ

ÊÇ

CVE-2020-2189

RCE

ÖÐΣ

ÊÇ


0x01 ·ì϶ÏêÇé


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



CloudBees Jenkins£¨Hudson Labs£©ÊÇÃÀ¹úCloudBees¹«Ë¾µÄÒ»Ì×»ùÓÚJava¿ª·¢µÄ³ÖÐø¼¯³É¹¤¾ß ¡£¸Ã²úÆ·ÖØÒªÓÃÓÚ¼à¿Ø³ÖÐøµÄÈí¼þ°æ±¾°ä²¼/²âÊÔÏîÄ¿ºÍһЩ°´Ê±Ö´ÐеŤ×÷ ¡£

2020Äê5ÔÂ6ÈÕ£¬Jenkins¹Ù·½°ä²¼°²È«²¼¸æ½¨¸´²å¼þÖеÄ9¸ö·ì϶£¬ÆäÖÐÓÐ5¸ö²å¼þÊܵ½Ó°Ïì ¡£¾ßÌåÄÚÈÝÈçÏ£º

Credentials Binding ²å¼þ´æÔÚÁ½¸öÍ´´¦Ð¹Â¶·ì϶£¨CVE-2020-2181¡¢CVE-2020-2182£©£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñÈ¡Ãô¸ÐÐÅÏ¢ ¡£

Copy Artifact ²å¼þ´æÔÚȨÏÞУÑé²»µ±·ì϶£¨CVE-2020-2183£©£¬¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úÆ·ÖжÌȱÉí·ÝÑéÖ¤´ëÊ©»òÉí·ÝÑé֤ǿ¶È²»¼° ¡£

CVS ²å¼þ´æÔÚ¿çÕ¾ÒªÇóαÔì·ì϶£¨CVE-2020-2184£©£¬¸Ã·ì϶ԴÓÚWEBÀûÓÃδ³ä·ÖÑéÖ¤ÒªÇóÊÇ·ñÀ´×Ô¿ÉÐÅÓþ»§ ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ͨ¹ýÊÜÓ°Ïì¿Í»§¶ËÏò·þÎñÆ÷·¢ËÍ·ÇÔ¤ÆÚµÄÒªÇó ¡£

Amazon EC2 ²å¼þ´æÔÚ4 ¸ö·ì϶£¨CVE-2020-2185¡¢CVE-2020-2186¡¢CVE-2020-2187¡¢CVE-2020-2188£© ¡£CVE-2020-2185Ô´ÓÚ²»×ã¶ÔSSHÖ÷»úÃÜÔ¿µÄÑéÖ¤ ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐÖÐÑëÈ˹¥»÷ ¡£CVE-2020-2186Ô´ÓÚWEBÀûÓÃδ³ä·ÖÑéÖ¤ÒªÇóÊÇ·ñÀ´×Ô¿ÉÐÅÓþ»§ ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ͨ¹ýÊÜÓ°Ïì¿Í»§¶ËÏò·þÎñÆ÷·¢ËÍ·ÇÔ¤ÆÚµÄÒªÇó ¡£CVE-2020-2187Ô´ÓÚ·¨Ê½Ã»ÓÐÑéÖ¤SSL/TLSÖ¤ÊéºÍÖ÷»úÃû ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐÖÐÑëÈ˹¥»÷ ¡£CVE-2020-2188Ô´ÓÚÍøÂçϵͳ»ò²úÆ·ÖжÌȱÉí·ÝÑéÖ¤´ëÊ©»òÉí·ÝÑé֤ǿ¶È²»¼° ¡£

SCM Filter Jervis²å¼þ´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-2189£©£¬¸Ã·ì϶ԴÓÚSCM Filter Jervis²å¼þĬÈϲ»ÅäÖÃYAML½âÎöÆ÷£¬µ¼ÖÂÓû§Äܹ»Ê¹ÓùýÂËÆ÷ÅäÖÃÏîÄ¿£¬Ò²Äܹ»²Ù×÷SCMÒÑ´æ´¢ÅäÖùýµÄÏîÄ¿ÄÚÈÝ ¡£


0x02 ·ì϶¼ì²â


½¨ÒéÓйØÓû§¾¡¿ì²é¿´µ±Ç°Ê¹ÓõIJå¼þ°æ±¾£¬È·ÈÏÊÇ·ñÔÚÊÜÓ°ÏìÁìÓòÄÚ£¬²¢ÊµÊ±Éý¼¶ÖÁ°²È«°æ±¾½øÐзÀ»¤£¬²Ù×÷²½ÖèÈçÏ£º

µã»÷¡°Manage Jenkins¡±½øÈëÖÎÀíÄ £¿é£¬Ñ¡Ôñ¡°Manage Plugins¡±ÖÎÀí²å¼þ ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



µã»÷¡°installed¡±¼´¿É¶Ôµ±Ç°ÒÑ×°ÖõIJå¼þ°æ±¾½øÐв鿴 ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



0x03 ´ëÖý¨Òé


ĿǰJenkins¹Ù·½ÒѾ­Õë¶ÔÕâ´Î·ì϶°ä²¼ÁËеIJå¼þ°æ±¾£¬ÇëÓйØÓû§¾¡¿ìÉý¼¶ÊÜÓ°ÏìµÄ²å¼þÖÁ°²È«°æ±¾£¬²Ù×÷²½ÖèÈçÏ£º

ÔÚ²å¼þÖÎÀí½çÃæÑ¡Ôñ±ØÒªÉý¼¶µÄ²å¼þ£¬µã»÷¡°Download now and install after restart¡±½øÐиüвÙ×÷ ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



0x04 ÓйØÐÂÎÅ


https://www.openwall.com/lists/oss-security/2020/05/06/3


0x05 ²Î¿¼Á´½Ó


https://www.jenkins.io/security/advisory/2020-05-06/


0x06 ¹¦·òÏß


2020-05-06  Jenkins¹Ù·½°ä²¼²¼¸æ

2020-05-08 VSRC°ä²¼·ì϶¹«¸æ




±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾