En

Jenkins官网安全更新(2021-01-13)

来源:Jenkins官网 发布日期:2021-01-13 阅读次数:4375 评论:0

基本信息

发布日期:2021-01-13(官方当地时间)

更新类型:安全更新

更新版本:未知

感知时间:2021-01-14 00:03:45

风险等级:未知

情报贡献:TSRC

更新标题

Jenkins Security Advisory 2021-01-13

更新详情

XSS vulnerability in notification barSECURITY-1889
/
CVE-2021-21603Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents (typically shown after form submissions via Apply button).This results in a cross-site scripting (XSS) vulnerability exploitable by attackers able to influence notification bar contents.Jenkins 2.275, LTS 2.263.2 escapes the content shown in notification bars.Stored XSS vulnerability in button labelsSECURITY-2035
/
CVE-2021-21608Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape button labels in the Jenkins UI.This results in a cross-site scripting vulnerability exploitable by attackers with the ability to control button labels.
An example of buttons with a user-controlled label are the buttons of the Pipeline input step.Jenkins 2.275, LTS 2.263.2 escapes button labels in the Jenkins UI.Reflected XSS vulnerability in markup formatter previewSECURITY-2153
/
CVE-2021-21610Jenkins allows administrators to choose the markup formatter to use for descriptions of jobs, builds, views, etc. displayed in Jenkins.
When editing such a description, users can choose to have Jenkins render a formatted preview of the description they entered.Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not implement any restrictions for the URL rendering the formatted preview of markup passed as a query parameter.
This results in a reflected cross-site scripting (XSS) vulnerability if the configured markup formatter does not prohibit unsafe elements (JavaScript) in markup, like Anything Goes Formatter Plugin.Jenkins 2.275, LTS 2.263.2 requires that preview URLs are accessed using POST and sets Content-Security-Policy headers that prevent execution of unsafe elements when the URL is accessed directly.NoteIn case of problems with this change, these protections can be disabled by setting the Java system properties hudson.markup.MarkupFormatter.previewsAllowGET to true and/or hudson.markup.MarkupFormatter.previewsSetCSP to false.
Doing either is discouraged.Stored XSS vulnerability on new item pageSECURITY-2171
/
CVE-2021-21611Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape display names and IDs of item types shown on the New Item page.This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to specify display names or IDs of item types.NoteAs of the publication of this advisory, the Jenkins security team is not aware of any plugins published via the Jenkins project update center that allow doing this.Jenkins 2.275, LTS 2.263.2 escapes display names and IDs of item types shown on the New Item page.Improper handling of REST API XML deserialization errorsSECURITY-1923
/
CVE-2021-21604Jenkins provides XML REST APIs to configure views, jobs, and other items.
When deserialization fails because of invalid data, Jenkins 2.274 and earlier, LTS 2.263.1 and earlier stores invalid object references created through these endpoints in the Old Data Monitor.
If an administrator discards the old data, some erroneous data submitted to these endpoints may be persisted.This allows attackers with View/Create, Job/Create, Agent/Create, or their respective */Configure permissions to inject crafted content into Old Data Monitor that results in the instantiation of potentially unsafe objects when discarded by an administrator.Jenkins 2.275, LTS 2.263.2 does not record submissions from users in Old Data Monitor anymore.In case of problems, the Java system properties hudson.util.RobustReflectionConverter.recordFailuresForAdmins and hudson.util.RobustReflectionConverter.recordFailuresForAllAuthentications can be set to true to record configuration data submissions from administrators or all users, partially or completely disabling this fix.Arbitrary file read vulnerability in workspace browsersSECURITY-1452
/
CVE-2021-21602The file browser for workspaces, archived artifacts, and $JENKINS_HOME/userContent/ follows symbolic links to locations outside the directory being browsed in Jenkins 2.274 and earlier, LTS 2.263.1 and earlier.This allows attackers with Job/Workspace permission and the ability to control workspace contents (e.g., with Job/Configure permission or the ability to change SCM contents) to create symbolic links that allow them to access files outside workspaces using the workspace browser.NoteThis issue is caused by an incomplete fix for SECURITY-904 / CVE-2018-1000862 in the 2018-12-08 security advisory.Jenkins 2.275, LTS 2.263.2 no longer supports symlinks in workspace browsers.
While they may still exist on the file system, they are no longer shown on the UI, accessible via URLs, or included in directory content downloads.This fix only changes the behavior of the Jenkins UI.
Archiving artifacts still behaves as before.Path traversal vulnerability in agent namesSECURITY-2021
/
CVE-2021-21605Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with Agent/Configure permission to choose agent names that cause Jenkins to override unrelated config.xml files.
If the global config.xml file is replaced, Jenkins will start up with unsafe legacy defaults after a restart.Jenkins 2.275, LTS 2.263.2 ensures that agent names are considered valid names for items to prevent this problem.In case of problems, this change can be reverted by setting the Java system property jenkins.model.Nodes.enforceNameRestrictions to false.Arbitrary file existence check in file fingerprintsSECURITY-2023
/
CVE-2021-21606Jenkins provides a feature for jobs to store and track fingerprints of files used during a build.
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier provides a REST API to check where a given fingerprint was used by which builds.
This endpoint does not fully validate that the provided fingerprint ID is properly formatted before checking for the XML metadata for that fingerprint on the controller file system.This allows attackers with Overall/Read permission to check for the existence of XML files on the controller file system where the relative path can be constructed as 32 characters.Jenkins 2.275, LTS 2.263.2 validates that a fingerprint ID is properly formatted before checking for its existence.Excessive memory allocation in graph URLs leads to denial of serviceSECURITY-2025
/
CVE-2021-21607Jenkins renders several different graphs for features like agent and label usage statistics, memory usage, or various plugin-provided statistics.Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not limit the graph size provided as query parameters.This allows attackers to request or to have legitimate Jenkins users request crafted URLs that rapidly use all available memory in Jenkins, potentially leading to out of memory errors.Jenkins 2.275, LTS 2.263.2 limits the maximum size of graphs to an area of 10 million pixels.
If a larger size is requested, the default size for the graph will be rendered instead.This threshold can be configured by setting the Java system property hudson.util.Graph.maxArea to a different number on startup.Missing permission check for paths with specific prefixSECURITY-2047
/
CVE-2021-21609Jenkins includes a static list of URLs that are always accessible even without Overall/Read permission, such as the login form.
These URLs are excluded from an otherwise universal permission check.Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly compare requested URLs with that list.This allows attackers without Overall/Read permission to access plugin-provided URLs with any of the following prefixes if no other permissions are required:accessDeniederrorinstance-identityloginlogoutoopssecurityRealmsignuptcpSlaveAgentListenerFor example, a plugin contributing the path loginFoo/ would have URLs in that space accessible without the default Overall/Read permission check.The Jenkins security team is not aware of any affected plugins as of the publication of this advisory.The comparison of requested URLs with the list of always accessible URLs has been fixed to only allow access to the specific listed URLs in Jenkins 2.275, LTS 2.263.2.In case this change causes problems, additional paths can be made accessible without Overall/Read permissions:
The Java system property jenkins.model.Jenkins.additionalReadablePaths is a comma-separated list of additional path prefixes to allow access to.Credentials stored in plain text by TraceTronic ECU-TEST PluginSECURITY-2057
/
CVE-2021-21612TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file de.tracetronic.jenkins.plugins.ecutest.report.atx.installation.ATXInstallation.xml on the Jenkins controller as part of its configuration.These credentials can be viewed by users with access to the Jenkins controller file system.TraceTronic ECU-TEST Plugin 2.24 adds a new option type for sensitive options.
Previously stored credentials are migrated to that option type on Jenkins startup.XSS vulnerability in TICS PluginSECURITY-2098
/
CVE-2021-21613TICS Plugin 2020.3.0.6 and earlier does not escape TICS service responses.This results in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control TICS service response content.TICS Plugin 2020.3.0.7 escapes TICS service responses, or strips HTML out, as appropriate.Credentials stored in plain text by Bumblebee HP ALM PluginSECURITY-2156
/
CVE-2021-21614Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file com.agiletestware.bumblebee.BumblebeeGlobalConfig.xml on the Jenkins controller as part of its configuration.These credentials can be viewed by users with access to the Jenkins controller file system.Bumblebee HP ALM Plugin 4.1.6 stores credentials encrypted once its configuration is saved again.SeveritySECURITY-1452:MediumSECURITY-1889:HighSECURITY-1923:HighSECURITY-2021:HighSECURITY-2023:MediumSECURITY-2025:MediumSECURITY-2035:HighSECURITY-2047:LowSECURITY-2057:LowSECURITY-2098:HighSECURITY-2153:HighSECURITY-2156:LowSECURITY-2171:HighAffected VersionsJenkins weekly up to and including
2.274Jenkins LTS up to and including
2.263.1Bumblebee HP ALM
Pluginup to and including
4.1.5TICS
Pluginup to and including
2020.3.0.6TraceTronic ECU-TEST
Pluginup to and including
2.23.1FixJenkins weekly should be updated to version
2.275Jenkins LTS should be updated to version
2.263.2Bumblebee HP ALM
Pluginshould be updated to version
4.1.6TICS
Pluginshould be updated to version
2020.3.0.7TraceTronic ECU-TEST
Pluginshould be updated to version
2.24These versions include fixes to the vulnerabilities described above. All prior versions are considered to be affected by these vulnerabilities unless otherwise indicated.

软件描述

Jenkins是一个开源软件项目,是基于Java开发的一种持续集成工具,用于监控持续重复的工作,旨在提供一个开放易用的软件平台,使软件的持续集成变成可能。 [1]

TSRC分析

暂无

业界资讯

暂无

评论

提交评论 您输入的评论有误,请重新输入