CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2017-1000353Jenkins Multiple Security Vulnerabilities (Security Advisory 2017-04-26)

2017年5月22日 1430点热度 0人点赞 0条评论

漏洞类别:CGI

漏洞等级:

漏洞信息

Jenkins is an open source automation server written in Java.

Jenkins contains the following security vulnerabilities:
CVE-2017-1000353: An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would be deserialized using a new ObjectInputStream, bypassing the existing blacklist-based protection mechanism.
CVE-2017-1000354: The login command available in the remoting-based CLI stored the encrypted user name of the successfully authenticated user in a cache file used to authenticate further commands. Users with sufficient permission to create secrets in Jenkins, and download their encrypted values (e.g. with Job/Configure permission), were able to impersonate any other Jenkins user on the same instance.
CVE-2017-1000355: Jenkins uses the XStream library to serialize and deserialize XML. Its maintainer recently published a security vulnerability that allows anyone able to provide XML to Jenkins for processing using XStream to crash the Java process. In Jenkins this typically applies to users with permission to create or configure items (jobs), views, or agents.
CVE-2017-1000356: Multiple Cross-Site Request Forgery vulnerabilities in Jenkins allowed malicious users to perform several administrative actions by tricking a victim into opening a web page.

Affected Versions:
Jenkins (weekly) prior to 2.57
Jenkins (LTS) prior to 2.46.2

QID Detection Logic:
This unauthenticated QID matches the exposed X-Jenkins header value to detect vulnerable versions.

漏洞危害

Depending on the vulnerability being exploited, an unauthenticated, remote attacker could execute arbitrary code, conduct cross-site request forgery attacks, impersonate other Jenkins user or cause a denial-of-service vulnerability on the targeted system.

解决方案

Customers are advised to upgrade to Jenkins 2.46.2, 2.57 or later versions to remediate these vulnerabilities.

Patch:
Following are links for downloading patches to fix the vulnerabilities:

Jenkins 2.46.2, 2.57 or later

0daybank

标签: 暂无
最后更新:2017年5月22日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me