Èí¼þ¼¯³Éƽ̨Jenkins¶à¸öÎó²î
2017-04-29
ÍâµØÊ±¼ä2017Äê4ÔÂ26ÈÕ£¨±±¾©Ê±¼ä2017Äê4ÔÂ27ÈÕ£©£¬Èí¼þ¼¯³Éƽ̨Jenkins¹Ù·½Ðû²¼ÁËÇ徲ͨ¸æ£¬°üÀ¨Á˸üÐÂÐÞ¸´³ÌÐò£¬ÐÞ¸´ÁËÊý¸öÇå¾²Îó²î£¨CVE-2017-1000356£¬CVE-2017-1000353£¬CVE-2017-1000354£¬CVE-2017-1000355£©¡£
²Î¿¼Á´½Ó£º
http://www.securityfocus.com/bid/98056/info
http://seclists.org/oss-sec/2017/q2/132
https://jenkins.io/security/advisory/2017-04-26/
Îó²î¼òÊö
CVE-2017-1000356
°üÀ¨¶à¸öCSRFÎó²î£¬¿ÉÒÔʹJenkinsÁ¬Ã¦»òÑÓÊ±ÖØÆô£¬É¾³ýËùÓÐÉèÖõĸüÐÂÕ¾µã£¬×°ÖúͼÓÔØÈκÎÔÚÉèÖõĸüÐÂÕ¾µãÉÏ¿ÉÓõIJå¼þ£¬¸ü¸ÄJenkinsϵͳ£¬Çå¾²ºÍ¹¤¾ßÉèÖ㬻ò½¨ÉèеÄÊðÀíµÈ¡£
CVE-2017-1000353
¸ÃÎó²î¿ÉÒÔʹ¹¥»÷ÕßÔ¶³ÌԽȨִÐдúÂ룬½«ÐòÁл¯µÄJava SignedObject¹¤¾ß´«Êäµ½»ùÓÚremotingµÄJenkins CLI£¬½«Ê¹ÓÃеķ´ÐòÁл¯ObjectInputStream£¬ÈƹýÏÖÓеĻùÓÚºÚÃûµ¥µÄ±£»¤»úÖÆ¡£
CVE-2017-1000354
Ô¶³ÌµÄCLI½«Ö®Ç°Í¨¹ýÑéÖ¤µÄÓû§µÄ¼ÓÃܵǼÐÅÏ¢Öü±£´æÒ»¸ö»º´æÎļþÖУ¬ÕâЩÐÅÏ¢¿ÉÒÔÓÃÀ´ÑéÖ¤½øÒ»²½µÄÏÂÁî¡£ÓµÓÐÔÚJenkins½¨ÉèÉñÃØÈ¨ÏÞµÄÓû§¿ÉÒÔÓôËÎó²îÀ´Ã°³äµ±ºÎÒ»¸öÔÚͬÑùʵÀýÏÂµÄÆäËûJenkinsÓû§¡£
CVE-2017-1000355
JenkinsʹÓÃXStream¿âÀ´ÐòÁл¯ºÍ·´ÐòÁл¯XML¡£ËüµÄά»¤Õß×î½üÐû²¼ÁËÒ»¸öÇå¾²Îó²î£¬ÈκÎÄܹ»ÏòJenkinsÌṩXML²¢Ê¹ÓÃXStreamµÄÓû§¶¼¿ÉÒÔʹJavaÀú³ÌÍ߽⡣JenkinsÖУ¬Õâͨ³£ÊÊÓÃÓÚÓÐȨ½¨Éè»òÉèÖÃÏîÄ¿£¨×÷Òµ£©£¬ÊÓͼ»òÊðÀíµÄÓû§¡£
ÏêϸµÄÎó²îÏà¹ØÐÅÏ¢£¬Çë²Î¿¼ÒÔÏÂÁ´½Ó£ºhttps://jenkins.io/security/advisory/2017-04-26/
ÊÜÓ°ÏìµÄ°æ±¾
Jenkins Version <= 2.56Jenkins LTS Version <= 2.46.1
²»ÊÜÓ°ÏìµÄ°æ±¾
Jenkins Version 2.57Jenkins LTS Version 2.46.2
¹æ±Ü¼Æ»®
Jenkins¹Ù·½ÒѾÌṩÁËаæÔÀ´ÐÞ¸´ÉÏÊö¸÷Îó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶µ½Ð°汾£¬ÏÂÔØÁ´½ÓÈçÏ£º
https://jenkins.io/download/
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ







