Jenkins½¨¸´¶à¸ö°²È«·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-07-25
·ì϶±àºÅºÍ¼¶±ð
CVE-2018-1999001  ³§ÉÌ×ÔÆÀ£º¸ß  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999002  ³§ÉÌ×ÔÆÀ£º¸ß  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999003  ³§ÉÌ×ÔÆÀ£ºÖР CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999004  ³§ÉÌ×ÔÆÀ£ºÖР CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999005  ³§ÉÌ×ÔÆÀ£ºÖР CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999006  ³§ÉÌ×ÔÆÀ£ºÖР CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE-2018-1999007  ³§ÉÌ×ÔÆÀ£ºÖР CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾

Jenkins weekly 2.132 ÒÔ¼°¸üÔçµÄ°æ±¾

Jenkins LTS 2.121.1 ÒÔ¼°¸üÔçµÄ°æ±¾


·ì϶¸ÅÊö
JenkinsÊÇÒ»¸ö¿ªÔ´Èí¼þÏîÄ¿£¬ £¬£¬£¬£¬£¬£¬£¬ÊÇ»ùÓÚJava¿ª·¢µÄÒ»ÖÖ³ÖÐø¼¯³É¹¤¾ß£¬ £¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ¼à¿Ø³ÖÐø³Á¸´µÄ¹¤×÷£¬ £¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÌṩһ¸öÊ¢¿ªÒ×ÓõÄÈí¼þƽ̨£¬ £¬£¬£¬£¬£¬£¬£¬Ê¹Èí¼þµÄ³ÖÐø¼¯³ÉÔì³É¿ÉÄÜ¡£¡£¡£¡£¡£¡£¡£

Jenkins ¹Ù·½ÔÚ 7 Ô 18 ºÅ°ä²¼Á˰²È«×ÊѶ£¬ £¬£¬£¬£¬£¬£¬£¬¶ÔÁ½¸ö¸ßΣºÍ5¸öÖм¶·ì϶½øÐй«¸æ£º https://jenkins.io/security/advisory/2018-07-18/¡£¡£¡£¡£¡£¡£¡£


CVE-2018-1999001ÅäÖÃÎļþõ辶Ťתµ¼ÖÂÖÎÀíԱȨÏÞÊ¢¿ª·ì϶
Ô¶³ÌÇÒδ¾­ÊÚȨµÄ¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâµÇ¼ƾ֤£¬ £¬£¬£¬£¬£¬£¬£¬´ÓJenkins Ö÷Ŀ¼ÏÂÒÆ³ý config.xml ÅäÖÃÎļþµ½ÆäËûĿ¼£¬ £¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö Jenkins ·þÎñÏ´γÁÆôʱÍË»Ø legacy ģʽ£¬ £¬£¬£¬£¬£¬£¬£¬¶ÔÄäÃûÓû§Ò²»áÊ¢¿ªÖÎÀíԱȨÏÞ£¬ £¬£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º

 

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


´Ë·ì϶ÀûÓõÄǰÌáÊDZØÒªÆÚ´ý Jenkins ·þÎñµÄ³ÁÆô¡£¡£¡£¡£¡£¡£¡£


ΪÁË»º½â´ËÎÊÌ⣬ £¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÇ¿ÁÒ½¨ÒéûÓд˽¨¸´·¨Ê½µÄJenkinsÊ·ýµÄÖÎÀíÔ±Äܹ»Óɲ»ÊÜÐÅÀµµÄÓû§½Ó¼û£¬ £¬£¬£¬£¬£¬£¬£¬ÔڹعØJenkins֮ǰ²»¾Ã±£ÁôÈ«¾ÖÅäÖᣡ£¡£¡£¡£¡£¡£ÕâÑù×ö»á½«µ±Ç°ÅäÖôÓÄÚ´æÐ´Èëconfig.xmlÎļþ£¬ £¬£¬£¬£¬£¬£¬£¬¸ÃÎļþ½öÔÚÆô¶¯Ê±»ò³ÁмÓÔØÅäÖÃʱ¶ÁÈ¡¡£¡£¡£¡£¡£¡£¡£

ÈôÊÇÔÚÀûÓôËÎÊÌâºóJenkinsÒѾ­¹Ø¹Ø£¬ £¬£¬£¬£¬£¬£¬£¬ÔòÄܹ»ÔÚJenkinsÖ÷Ŀ¼ÖеÄusers/$002e$002e/config.xmlÖÐÕÒµ½config.xmlÎļþ¡£¡£¡£¡£¡£¡£¡£


CVE-2018-1999002ËÁÒâÎļþ¶ÁÈ¡·ì϶

Jenkins ʹÓÃµÄ Stapler Web ¿ò¼Ü´æÔÚËÁÒâÎļþ¶ÁÈ¡·ì϶¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚÔ¶³ÌÇÒδ¾­ÊÚȨµÄÇé¿öÏ£¬ £¬£¬£¬£¬£¬£¬£¬Äܹ»Í¨¹ý»ú¹Ø¶ñÒâµÄ HTTP ÒªÇó·¢Íù Jenkins Web ·þÎñ¶Ë£¬ £¬£¬£¬£¬£¬£¬£¬´ÓÒªÇóÏìÓ¦ÖÐÖ±½Ó»ñÈ¡¹¥»÷ÕßÖ¸¶¨¶ÁÈ¡µÄÎļþÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£


´Ó¹Ù·½Ìá½»µÄ°²È«²âÊÔ²¹¶¡ÖУ¬ £¬£¬£¬£¬£¬£¬£¬Äܹ»¿´³ö£¬ £¬£¬£¬£¬£¬£¬£¬´Ë·ì϶ÊÇÔÚ HTTP ÒªÇóÍ· Accept-Language ÖнøÐжñÒâÊý¾Ý»ú¹Ø£¬ £¬£¬£¬£¬£¬£¬£¬²¢ÖØÒªÕë¶Ô Windows ϵͳ£¨ÔÚ Linux ϵͳÉÏÀûÓÃÔò±ØÒªÂú×ãÌØ¶¨Ç°Ìᣩ£º

 

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


²âÊÔ·¢ÏÖ´Ë·ì϶µÄÀûÓñØÒª¿ªÆôÄäÃûÓû§½Ó¼ûȨÏÞ£¨²âÊ԰汾Ϊ Jenkins LTS 2.121.1£©¡£¡£¡£¡£¡£¡£¡£

StaplerÖеÄÊäÈëÑéÖ¤Òѵõ½¸Ä½ø£¬ £¬£¬£¬£¬£¬£¬£¬ÒÔÔ¤·ÀÕâÖÖÇé¿ö²úÉú¡£¡£¡£¡£¡£¡£¡£


CVE-2018-1999003δ¾­ÊÚȨµÄÓû§Äܹ»È¡µÞÁжӵĹ¹½¨
´¦ÖÃÁжӹ¹½¨È¡µÞµÄURLδִÐÐȨÏ޲鳭£¬ £¬£¬£¬£¬£¬£¬£¬ÔÊÐí¾ßÓÓ×°×ÜÌå/¶ÁÈ¡¡±È¨ÏÞµÄÓû§È¡µÞÁжӹ¹½¨¡£¡£¡£¡£¡£¡£¡£

´¦ÖÃÁжӹ¹½¨µÄÈ¡µÞµÄURL´Ë¿ÌÈ·±£Óû§ÓµÓÐÏîÄ¿/È¡µÞȨÏÞ¡£¡£¡£¡£¡£¡£¡£


CVE-2018-1999004δ¾­ÊÚȨµÄÓû§Äܹ»Æô¶¯ºÍ¶ôÖÆ´úÀíÆô¶¯
ÔÚJenkinsÖ÷·þÎñÆ÷ÉÏÆô¶¯´úÀíÆô¶¯µÄURLδִÐÐȨÏ޲鳭£¬ £¬£¬£¬£¬£¬£¬£¬ÔÊÐí¾ßÓÓ×°×ÜÌå/¶ÁÈ¡¡±È¨ÏÞµÄÓû§Æô¶¯´úÀíÆô¶¯¡£¡£¡£¡£¡£¡£¡£
ÕâÑù×öÈ¡µÞÁËÖ¸¶¨´úÀí·¨Ê½µÄËùÓÐÔÚ½øÐÐµÄÆô¶¯£¬ £¬£¬£¬£¬£¬£¬£¬Òò¶øÕâÔÊÐí¹¥»÷Õß×èÖ¹´úÀíÎÞÆÚÏÞÆô¶¯¡£¡£¡£¡£¡£¡£¡£

´Ë¿Ì£¬ £¬£¬£¬£¬£¬£¬£¬´úÀíÆô¶¯µÄURL¿ÉÈ·±£Óû§¾ßÓÓ×°´úÀí/Ïνӡ±È¨ÏÞ¡£¡£¡£¡£¡£¡£¡£


CVE-2018-1999005´æ´¢µÄXSS·ì϶
ÔÚÏñ/ view / ... / buildsÕâÑùµÄURLÉÏÏÔʾµÄ¹¹½¨¹¦·òÏßÓײ¿¼þûÓÐÕýÈ·µØ×ªÒåÏîÖ÷ÕÅÏÔʾÃû³Æ¡£¡£¡£¡£¡£¡£¡£Õâµ¼ÖÂÁË¿ÉÄܽÚÔìÏîÄ¿ÏÔʾÃû³ÆµÄÓû§¿ÉÀûÓõĿçÕ¾µã¾ç±¾·ì϶¡£¡£¡£¡£¡£¡£¡£

Jenkins´Ë¿ÌתÒ幦·òÏßÓײ¿¼þÉÏÏÔʾµÄ×÷ÒµÏÔʾÃû³Æ¡£¡£¡£¡£¡£¡£¡£


CVE-2018-1999006δ¾­ÊÚȨµÄÓû§Äܹ»È·¶¨ºÎʱ´ÓÆäJPI°üÖÐÌáÈ¡²å¼þ
ÅúʾºÎʱ½«²å¼þJPIÎļþ×îºóÌáÈ¡µ½JenkinsÖ÷Ŀ¼ÖеIJå¼þ/×ÓĿ¼ÖеÄÎļþ¿ÉÓÉÓµÓÐ×ÜÌå/¶ÁȡȨÏÞµÄÓû§Í¨¹ýHTTP½Ó¼û¡£¡£¡£¡£¡£¡£¡£ÕâÔÊÐíδ¾­ÊÚȨµÄÓû§È·¶¨¸ø¶¨²å¼þµÄ¿ÉÄÜ×°ÖÃÈÕÆÚ¡£¡£¡£¡£¡£¡£¡£

ÊÜÓ°ÏìµÄÎļþ²»ÔÙͨ¹ýHTTPÌṩ¡£¡£¡£¡£¡£¡£¡£


CVE-2018-1999007 Staplerµ÷ÊÔģʽϵÄXSS·ì϶
StaplerÊÇJenkinsÓÃÓÚ·ÓÉHTTPÒªÇóµÄWeb¿ò¼Ü¡£¡£¡£¡£¡£¡£¡£ÆôÓÃÆäµ÷ÊÔģʽºó£¬ £¬£¬£¬£¬£¬£¬£¬HTTP 404ÃýÎóÒ³Ãæ½«ÏÔʾÕï¶ÏÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÕâЩÃýÎóÒ³ÃæÃ»ÓÐÌÓ±ÜËüÃÇÏÔʾµÄ²¿ÃÅURL£¬ £¬£¬£¬£¬£¬£¬£¬ÔÚ¼«ÉÙÊýÇé¿öÏ»ᵼÖ¿çÕ¾µã¾ç±¾·ì϶¡£¡£¡£¡£¡£¡£¡£
´Ë¿ÌÄܹ»ÕýȷתÒåÕâЩÃýÎóÒ³ÃæÉÏÏÔʾµÄ²¿ÃÅURL¡£¡£¡£¡£¡£¡£¡£

×÷Ϊ½â¾ö²½Ö裬 £¬£¬£¬£¬£¬£¬£¬²»Ó¦ÔÚStaplerµ÷ÊÔģʽ϶Բ»ÊÜÐÅÀµµÄÓû§¿É½Ó¼ûµÄÊ·ýÆôÓÃStaplerµ÷ÊÔģʽ¡£¡£¡£¡£¡£¡£¡£


½¨¸´½¨Ò飺
Óû§Ó¦ÊµÊ±Éý¼¶½øÐзÀ»¤£º
Jenkins weekly Éý¼¶µ½ 2.133 °æ±¾

Jenkins LTS Éý¼¶µ½ 2.121.2 °æ±¾


²Î¿¼Á´½Ó£º
https://jenkins.io/security/advisory/2018-07-18/
https://github.com/jenkinsci/jenkins/commit/d71ac6ffe98ee62e0353af7a948a4ae1a69b67e9