{"id":104449,"date":"2022-04-22T10:31:50","date_gmt":"2022-04-22T12:31:50","guid":{"rendered":"https:\/\/teknomers.com\/fr\/un-chercheur-publie-un-poc-pour-une-recente-vulnerabilite-cryptographique-java\/"},"modified":"2022-04-22T10:31:56","modified_gmt":"2022-04-22T12:31:56","slug":"un-chercheur-publie-un-poc-pour-une-recente-vulnerabilite-cryptographique-java","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/un-chercheur-publie-un-poc-pour-une-recente-vulnerabilite-cryptographique-java\/","title":{"rendered":"Un chercheur publie un PoC pour une r\u00e9cente vuln\u00e9rabilit\u00e9 cryptographique Java"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Un code de preuve de concept (PoC) d\u00e9montrant une vuln\u00e9rabilit\u00e9 de contournement de signature num\u00e9rique r\u00e9cemment r\u00e9v\u00e9l\u00e9e dans Java a \u00e9t\u00e9 partag\u00e9 en ligne. <\/p>\n<p>Le <a rel=\"nofollow noopener\" href=\"https:\/\/openjdk.java.net\/groups\/vulnerability\/advisories\/2022-04-19\" target=\"_blank\">faille de grande gravit\u00e9<\/a> Dans la question, <a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-21449\" target=\"_blank\">CVE-2022-21449<\/a> (score CVSS\u00a0: 7,5), affecte la version suivante de Java SE et Oracle GraalVM Enterprise Edition &#8211;<\/p>\n<ul>\n<li>Oracle Java SE : 7u331, 8u321, 11.0.14, 17.0.2, 18<\/li>\n<li>Oracle GraalVM Enterprise Edition\u00a0: 20.3.5, 21.3.1, 22.0.0.2<\/li>\n<\/ul>\n<p>Le probl\u00e8me r\u00e9side dans l&#8217;impl\u00e9mentation par Java de l&#8217;algorithme de signature num\u00e9rique \u00e0 courbe elliptique (<a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/Elliptic_Curve_Digital_Signature_Algorithm\" target=\"_blank\">ECDSA<\/a>), un <a rel=\"nofollow noopener\" href=\"https:\/\/blog.cloudflare.com\/ecdsa-the-digital-signature-algorithm-of-a-better-internet\/\" target=\"_blank\">m\u00e9canisme cryptographique<\/a> pour <a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/Digital_signature\" target=\"_blank\">signer num\u00e9riquement<\/a> messages et donn\u00e9es permettant de v\u00e9rifier l&#8217;authenticit\u00e9 et l&#8217;int\u00e9grit\u00e9 du contenu.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/dset1\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/Nouveau-Wiper-Malware-ciblant-lUkraine-dans-le-cadre-de-loperation.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>En un mot, la b\u00e9vue cryptographique &#8211; surnomm\u00e9e Psychic Signatures en Java &#8211; permet de pr\u00e9senter une signature totalement vierge, qui serait toujours per\u00e7ue comme valide par l&#8217;impl\u00e9mentation vuln\u00e9rable.<\/p>\n<div class=\"separator\" style=\"clear: both\"><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"836\" data-original-width=\"728\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/04\/Un-chercheur-publie-un-PoC-pour-une-recente-vulnerabilite-cryptographique.gif\" \/><\/div>\n<p>L&#8217;exploitation r\u00e9ussie de la faille pourrait permettre \u00e0 un attaquant de falsifier des signatures et de contourner les mesures d&#8217;authentification mises en place.<\/p>\n<p>Le PoC, publi\u00e9 par le chercheur en s\u00e9curit\u00e9, Khaled Nassar <a rel=\"nofollow noopener\" href=\"https:\/\/github.com\/khalednassar\/CVE-2022-21449-TLS-PoC\" target=\"_blank\">implique<\/a> un client vuln\u00e9rable et un serveur TLS malveillant, dont le premier accepte une signature invalide du serveur, permettant effectivement au <a rel=\"nofollow noopener\" href=\"https:\/\/www.cloudflare.com\/learning\/ssl\/what-happens-in-a-tls-handshake\/\" target=\"_blank\">Prise de contact TLS<\/a> continuer sans entrave.<\/p>\n<p>&#8220;Il est difficile d&#8217;exag\u00e9rer la gravit\u00e9 de ce bogue&#8221;, a d\u00e9clar\u00e9 le chercheur de ForgeRock Neil Madden, qui a d\u00e9couvert et signal\u00e9 la faille le 11 novembre 2021, <a rel=\"nofollow noopener\" href=\"https:\/\/neilmadden.blog\/2022\/04\/19\/psychic-signatures-in-java\/\" target=\"_blank\">mentionn\u00e9<\/a>.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/crowdsec-tour-d\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/04\/1650021915_454_Haskers-Gang-donne-gratuitement-le-logiciel-malveillant-ZingoStealer-a-dautres.jpg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>&#8220;Si vous utilisez des signatures ECDSA pour l&#8217;un de ces m\u00e9canismes de s\u00e9curit\u00e9, un attaquant peut les contourner de mani\u00e8re triviale et compl\u00e8te si votre serveur ex\u00e9cute une version Java 15, 16, 17 ou 18.&#8221;<\/p>\n<p>Le probl\u00e8me a depuis \u00e9t\u00e9 r\u00e9solu par Oracle dans le cadre de sa mise \u00e0 jour trimestrielle du correctif critique (CPU) d&#8217;avril 2022. <a rel=\"nofollow noopener\" href=\"https:\/\/www.oracle.com\/security-alerts\/cpuapr2022.html\" target=\"_blank\">publi\u00e9<\/a> le 19 avril 2022.<\/p>\n<p>\u00c0 la lumi\u00e8re de la publication du PoC, il est recommand\u00e9 aux organisations qui utilisent Java 15, Java 16, Java 17 ou Java 18 dans leurs environnements de hi\u00e9rarchiser les correctifs pour att\u00e9nuer l&#8217;exploitation active.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/04\/researcher-releases-poc-for-recent-java.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Un code de preuve de concept (PoC) d\u00e9montrant une vuln\u00e9rabilit\u00e9 de contournement de signature num\u00e9rique r\u00e9cemment r\u00e9v\u00e9l\u00e9e dans Java a \u00e9t\u00e9 partag\u00e9 en ligne. Le faille de grande gravit\u00e9 Dans la question, CVE-2022-21449 (score CVSS\u00a0: 7,5), affecte la version suivante de Java SE et Oracle GraalVM Enterprise Edition &#8211; Oracle Java SE : 7u331, 8u321, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":104450,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[78,4168,30750,4158,4165,4161,4312,4157,4159,4171,4170,4167,4160,4163,4162,54039,185,2212,27730,4172,4169,196,4166,3667,4164],"class_list":["post-104449","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-chercheur","tag-comment-pirater","tag-cryptographique","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-java","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-poc","tag-pour","tag-publie","tag-recente","tag-securite-informatique","tag-securite-internet","tag-une","tag-violation-de-donnees","tag-vulnerabilite","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/104449","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=104449"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/104449\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/104450"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=104449"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=104449"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=104449"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}