CloudBees Jenkins Dependency Graph Viewer插件跨站脚本漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1663864 漏洞类型 跨站脚本
发布时间 2019-07-12 更新时间 2019-07-12
CVE编号 CVE-2019-10349 CNNVD-ID CNNVD-201907-638
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2019070063
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201907-638
|漏洞详情
CloudBees Jenkins(Hudson Labs)是美国CloudBees公司的一套基于Java开发的持续集成工具。该产品主要用于监控持续的软件版本发布/测试项目和一些定时执行的任务。Dependency Graph Viewer Plugin是使用在其中的一个依赖关系显示插件。 CloudBees Jenkins中的Dependency Graph Viewer插件0.13及之前版本存在跨站脚本漏洞。该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。
|漏洞EXP
# Exploit Title:  Persistent XSS - Dependency Graph View Plugin(v0.13)
# Vendor Homepage:
https://wiki.jenkins.io/display/JENKINS/Dependency+Graph+View+Plugin
# Exploit Author: Ishaq Mohammed
# Contact: https://twitter.com/security_prince
# Website: https://about.me/security-prince
# Category: webapps
# Platform: Java
# CVE: CVE-2019-10349
# Jenkins issue: #SECURITY-1177

1. Description:
The "Display Name" field in General Options of the Configure module in
Jenkins was found to be accepting arbitrary value which when loaded in the
Dependency Graph View module gets execute which makes it vulnerable to a
Stored/Persistent XSS.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10349
2. Proof of Concept:
Vulnerable Source
http://{jenkins-hostname:port}/jobs/{projectname}/configure
Steps to Reproduce:
Login to Jenkins Server with valid credentials and ensure that the
dependency graph plugin is installed.
1. Click on configure the Jenkins plugin.
2. Select advanced options
3. Enter the XSS payload in the "Display Name" field
4. Navigate to Dependency Graph module
5. Observe the Executed Payload
6. Payload used for the demo:

<img src="a" onerror="alert('jenkinsxss')">

3. Solution:
As of publication of this advisory, there is no fix.
The plugin hsa been abandoned by the maintainer


Reference
https://jenkins.io/security/advisory/2019-07-11/#SECURITY-1177

-- 
Best Regards,
Ishaq Mohammed
https://about.me/security-prince
|参考资料

来源:jenkins.io

链接:https://jenkins.io/security/advisory/2019-07-11/#SECURITY-1177


来源:www.openwall.com

链接:http://www.openwall.com/lists/oss-security/2019/07/11/4


来源:nvd.nist.gov

链接:https://nvd.nist.gov/vuln/detail/CVE-2019-10349


来源:vigilance.fr

链接:https://vigilance.fr/vulnerability/Jenkins-Plugins-multiple-vulnerabilities-29751