Jenkins Git Client²å¼þÔ¶³ÌºÅÁîÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-09-18¡ñ·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-10392£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º8.8
¡ñÓ°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
Git Client Plugin <= 2.8.4
¡ñ·ì϶¸ÅÊö
Jenkins Git Client²å¼þÖз¢ÏÖÔ¶³ÌºÅÁîÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£Git Client²å¼þΪJenkins²å¼þÌṩÁËgitÀûÓ÷¨Ê½±à³Ì½Ó¿Ú£¨API£©¡£¡£¡£¡£¡£¡£¡£ ËüÄܹ»»ñÈ¡£¬£¬£¬£¬£¬£¬£¬Ç©³ö£¬£¬£¬£¬£¬£¬£¬·ÖÖ§£¬£¬£¬£¬£¬£¬£¬ÁÐ±í£¬£¬£¬£¬£¬£¬£¬¹é²¢ºÍÏóÕ÷´æ´¢¿â¡£¡£¡£¡£¡£¡£¡£ Git Client½Ó¿ÚÌṩgit½Ó¼ûµÄÖØÒªÈë¿Úµã¡£¡£¡£¡£¡£¡£¡£ ËüÖ§³ÖJenkinsÍ´´¦²å¼þÌṩµÄÓû§Ãû/ÃÜÂëÍ´´¦ºÍ˽Կƾ֤¡£¡£¡£¡£¡£¡£¡£Õâ¸ö²å¼þ¾Ý¹Ù·½Êý¾Ý×°ÖÃÁ¿ÓÐ24Íò¶à£¬£¬£¬£¬£¬£¬£¬×°ÖÃÁ¿±ÈÁ¦´ó¡£¡£¡£¡£¡£¡£¡£
¸Ã·ì϶ԴÓÚGit¿Í»§¶Ë²å¼þ½ÓÊÜÓû§Ö¸¶¨µÄÖµ×÷ΪŲÓÃgit ls-remoteµÄ²ÎÊý£¬£¬£¬£¬£¬£¬£¬ÒÔÑéÖ¤Ö¸¶¨URL´¦ÊÇ·ñ´æÔÚGit´æ´¢¿â¡£¡£¡£¡£¡£¡£¡£ ÕâÊÇÒÔÔÊÐíÓµÓÐ×÷Òµ/ÅäÖÃȨÏ޵Ĺ¥»÷ÕßÔÚJenkinsÖ÷·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâϵͳºÅÁî×÷ΪJenkins¹ý³ÌÔÚÔËÐеÄOSÓû§µÄ·½Ê½ÊµÏֵġ£¡£¡£¡£¡£¡£¡£ÓÉÓÚ½Ó¹ÜÓû§ÊäÈëRepository URL¶øÃ»ÓÐ×ö¹ýÂË£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÁËÓëgit ls-remoteºÅÁîÆ´½Ó£¬£¬£¬£¬£¬£¬£¬Ö´ÐÐÁËÓû§¿É¿ØµÄºÅÁî¡£¡£¡£¡£¡£¡£¡£
¡ñ·ì϶ÑéÖ¤
EXP£ºhttps://iwantmore.pizza/posts/cve-2019-10392.html¡£¡£¡£¡£¡£¡£¡£
¡ñ½¨¸´½¨Òé
Éý¼¶Git Client Plugin£º
https://plugins.jenkins.io/git-client¡£¡£¡£¡£¡£¡£¡£
¡ñ²Î¿¼Á´½Ó
https://jenkins.io/security/advisory/2019-09-12/#SECURITY-1534


¾©¹«Íø°²±¸11010802024551ºÅ