Jenkins½¨¸´¶à¸ö°²È«·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-07-25CVE-2018-1999001 ³§ÉÌ×ÔÆÀ£º¸ß CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999002 ³§ÉÌ×ÔÆÀ£º¸ß CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999003 ³§ÉÌ×ÔÆÀ£ºÖÐ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999004 ³§ÉÌ×ÔÆÀ£ºÖÐ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999005 ³§ÉÌ×ÔÆÀ£ºÖÐ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999006 ³§ÉÌ×ÔÆÀ£ºÖÐ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1999007 ³§ÉÌ×ÔÆÀ£ºÖÐ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Jenkins weekly 2.132 ÒÔ¼°¸üÔçµÄ°æ±¾Jenkins LTS 2.121.1 ÒÔ¼°¸üÔçµÄ°æ±¾
JenkinsÊÇÒ»¸ö¿ªÔ´Èí¼þÏîÄ¿£¬£¬£¬£¬£¬£¬£¬£¬ÊÇ»ùÓÚJava¿ª·¢µÄÒ»ÖÖ³ÖÐø¼¯³É¹¤¾ß£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ¼à¿Ø³ÖÐø³Á¸´µÄ¹¤×÷£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÌṩһ¸öÊ¢¿ªÒ×ÓõÄÈí¼þƽ̨£¬£¬£¬£¬£¬£¬£¬£¬Ê¹Èí¼þµÄ³ÖÐø¼¯³ÉÔì³É¿ÉÄÜ¡£¡£¡£¡£¡£¡£¡£
Jenkins ¹Ù·½ÔÚ 7 Ô 18 ºÅ°ä²¼Á˰²È«×ÊѶ£¬£¬£¬£¬£¬£¬£¬£¬¶ÔÁ½¸ö¸ßΣºÍ5¸öÖм¶·ì϶½øÐй«¸æ£º https://jenkins.io/security/advisory/2018-07-18/¡£¡£¡£¡£¡£¡£¡£
Ô¶³ÌÇÒδ¾ÊÚȨµÄ¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâµÇ¼ƾ֤£¬£¬£¬£¬£¬£¬£¬£¬´ÓJenkins Ö÷Ŀ¼ÏÂÒÆ³ý config.xml ÅäÖÃÎļþµ½ÆäËûĿ¼£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö Jenkins ·þÎñÏ´γÁÆôʱÍË»Ø legacy ģʽ£¬£¬£¬£¬£¬£¬£¬£¬¶ÔÄäÃûÓû§Ò²»áÊ¢¿ªÖÎÀíԱȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º
´Ë·ì϶ÀûÓõÄǰÌáÊDZØÒªÆÚ´ý Jenkins ·þÎñµÄ³ÁÆô¡£¡£¡£¡£¡£¡£¡£
ÈôÊÇÔÚÀûÓôËÎÊÌâºóJenkinsÒѾ¹Ø¹Ø£¬£¬£¬£¬£¬£¬£¬£¬ÔòÄܹ»ÔÚJenkinsÖ÷Ŀ¼ÖеÄusers/$002e$002e/config.xmlÖÐÕÒµ½config.xmlÎļþ¡£¡£¡£¡£¡£¡£¡£
Jenkins ʹÓÃµÄ Stapler Web ¿ò¼Ü´æÔÚËÁÒâÎļþ¶ÁÈ¡·ì϶¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚÔ¶³ÌÇÒδ¾ÊÚȨµÄÇé¿öÏ£¬£¬£¬£¬£¬£¬£¬£¬Äܹ»Í¨¹ý»ú¹Ø¶ñÒâµÄ HTTP ÒªÇó·¢Íù Jenkins Web ·þÎñ¶Ë£¬£¬£¬£¬£¬£¬£¬£¬´ÓÒªÇóÏìÓ¦ÖÐÖ±½Ó»ñÈ¡¹¥»÷ÕßÖ¸¶¨¶ÁÈ¡µÄÎļþÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£
²âÊÔ·¢ÏÖ´Ë·ì϶µÄÀûÓñØÒª¿ªÆôÄäÃûÓû§½Ó¼ûȨÏÞ£¨²âÊ԰汾Ϊ Jenkins LTS 2.121.1£©¡£¡£¡£¡£¡£¡£¡£
StaplerÖеÄÊäÈëÑéÖ¤Òѵõ½¸Ä½ø£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÔ¤·ÀÕâÖÖÇé¿ö²úÉú¡£¡£¡£¡£¡£¡£¡£
´¦ÖÃÁжӹ¹½¨È¡µÞµÄURLδִÐÐȨÏ޲鳣¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐí¾ßÓÓ×°×ÜÌå/¶ÁÈ¡¡±È¨ÏÞµÄÓû§È¡µÞÁжӹ¹½¨¡£¡£¡£¡£¡£¡£¡£
´¦ÖÃÁжӹ¹½¨µÄÈ¡µÞµÄURL´Ë¿ÌÈ·±£Óû§ÓµÓÐÏîÄ¿/È¡µÞȨÏÞ¡£¡£¡£¡£¡£¡£¡£
ÔÚJenkinsÖ÷·þÎñÆ÷ÉÏÆô¶¯´úÀíÆô¶¯µÄURLδִÐÐȨÏ޲鳣¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐí¾ßÓÓ×°×ÜÌå/¶ÁÈ¡¡±È¨ÏÞµÄÓû§Æô¶¯´úÀíÆô¶¯¡£¡£¡£¡£¡£¡£¡£
ÕâÑù×öÈ¡µÞÁËÖ¸¶¨´úÀí·¨Ê½µÄËùÓÐÔÚ½øÐÐµÄÆô¶¯£¬£¬£¬£¬£¬£¬£¬£¬Òò¶øÕâÔÊÐí¹¥»÷Õß×èÖ¹´úÀíÎÞÆÚÏÞÆô¶¯¡£¡£¡£¡£¡£¡£¡£
´Ë¿Ì£¬£¬£¬£¬£¬£¬£¬£¬´úÀíÆô¶¯µÄURL¿ÉÈ·±£Óû§¾ßÓÓ×°´úÀí/Ïνӡ±È¨ÏÞ¡£¡£¡£¡£¡£¡£¡£
ÔÚÏñ/ view / ... / buildsÕâÑùµÄURLÉÏÏÔʾµÄ¹¹½¨¹¦·òÏßÓײ¿¼þûÓÐÕýÈ·µØ×ªÒåÏîÖ÷ÕÅÏÔʾÃû³Æ¡£¡£¡£¡£¡£¡£¡£Õâµ¼ÖÂÁË¿ÉÄܽÚÔìÏîÄ¿ÏÔʾÃû³ÆµÄÓû§¿ÉÀûÓõĿçÕ¾µã¾ç±¾·ì϶¡£¡£¡£¡£¡£¡£¡£
Jenkins´Ë¿ÌתÒ幦·òÏßÓײ¿¼þÉÏÏÔʾµÄ×÷ÒµÏÔʾÃû³Æ¡£¡£¡£¡£¡£¡£¡£
ÅúʾºÎʱ½«²å¼þJPIÎļþ×îºóÌáÈ¡µ½JenkinsÖ÷Ŀ¼ÖеIJå¼þ/×ÓĿ¼ÖеÄÎļþ¿ÉÓÉÓµÓÐ×ÜÌå/¶ÁȡȨÏÞµÄÓû§Í¨¹ýHTTP½Ó¼û¡£¡£¡£¡£¡£¡£¡£ÕâÔÊÐíδ¾ÊÚȨµÄÓû§È·¶¨¸ø¶¨²å¼þµÄ¿ÉÄÜ×°ÖÃÈÕÆÚ¡£¡£¡£¡£¡£¡£¡£
ÊÜÓ°ÏìµÄÎļþ²»ÔÙͨ¹ýHTTPÌṩ¡£¡£¡£¡£¡£¡£¡£
StaplerÊÇJenkinsÓÃÓÚ·ÓÉHTTPÒªÇóµÄWeb¿ò¼Ü¡£¡£¡£¡£¡£¡£¡£ÆôÓÃÆäµ÷ÊÔģʽºó£¬£¬£¬£¬£¬£¬£¬£¬HTTP 404ÃýÎóÒ³Ãæ½«ÏÔʾÕï¶ÏÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÕâЩÃýÎóÒ³ÃæÃ»ÓÐÌÓ±ÜËüÃÇÏÔʾµÄ²¿ÃÅURL£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ¼«ÉÙÊýÇé¿öÏ»ᵼÖ¿çÕ¾µã¾ç±¾·ì϶¡£¡£¡£¡£¡£¡£¡£
´Ë¿ÌÄܹ»ÕýȷתÒåÕâЩÃýÎóÒ³ÃæÉÏÏÔʾµÄ²¿ÃÅURL¡£¡£¡£¡£¡£¡£¡£
×÷Ϊ½â¾ö²½Ö裬£¬£¬£¬£¬£¬£¬£¬²»Ó¦ÔÚStaplerµ÷ÊÔģʽ϶Բ»ÊÜÐÅÀµµÄÓû§¿É½Ó¼ûµÄÊ·ýÆôÓÃStaplerµ÷ÊÔģʽ¡£¡£¡£¡£¡£¡£¡£
Óû§Ó¦ÊµÊ±Éý¼¶½øÐзÀ»¤£º
Jenkins weekly Éý¼¶µ½ 2.133 °æ±¾
Jenkins LTS Éý¼¶µ½ 2.121.2 °æ±¾
https://jenkins.io/security/advisory/2018-07-18/
https://github.com/jenkinsci/jenkins/commit/d71ac6ffe98ee62e0353af7a948a4ae1a69b67e9


¾©¹«Íø°²±¸11010802024551ºÅ