{"id":106071,"date":"2022-04-23T07:05:05","date_gmt":"2022-04-23T09:05:05","guid":{"rendered":"https:\/\/teknomers.com\/fr\/atlassian-supprime-des-correctifs-pour-la-vulnerabilite-critique-de-contournement-de-lauthentification-jira\/"},"modified":"2022-04-23T07:05:10","modified_gmt":"2022-04-23T09:05:10","slug":"atlassian-supprime-des-correctifs-pour-la-vulnerabilite-critique-de-contournement-de-lauthentification-jira","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/atlassian-supprime-des-correctifs-pour-la-vulnerabilite-critique-de-contournement-de-lauthentification-jira\/","title":{"rendered":"Atlassian supprime des correctifs pour la vuln\u00e9rabilit\u00e9 critique de contournement de l&#8217;authentification Jira"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Atlassian a publi\u00e9 un avertissement de s\u00e9curit\u00e9 concernant une vuln\u00e9rabilit\u00e9 critique dans son logiciel Jira qui pourrait \u00eatre exploit\u00e9e par un attaquant distant non authentifi\u00e9 pour contourner les protections d&#8217;authentification.<\/p>\n<p>Suivi comme <a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-0540\" target=\"_blank\"><strong>CVE-2022-0540<\/strong><\/a>, la faille est not\u00e9e 9,9 sur 10 sur le syst\u00e8me de notation CVSS et r\u00e9side dans le framework d&#8217;authentification de Jira, Jira Seraph.  Khoadha de Viettel Cyber \u200b\u200bSecurity a \u00e9t\u00e9 cr\u00e9dit\u00e9 d&#8217;avoir d\u00e9couvert et signal\u00e9 la faille de s\u00e9curit\u00e9.<\/p>\n<p>&#8220;Un attaquant distant non authentifi\u00e9 pourrait exploiter cela en envoyant une requ\u00eate HTTP sp\u00e9cialement con\u00e7ue pour contourner les exigences d&#8217;authentification et d&#8217;autorisation dans les actions WebWork \u00e0 l&#8217;aide d&#8217;une configuration affect\u00e9e&#8221;, Atlassian <a rel=\"nofollow noopener\" href=\"https:\/\/confluence.atlassian.com\/jira\/jira-security-advisory-2022-04-20-1115127899.html\" target=\"_blank\">c&#8217;est not\u00e9<\/a>.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/backhub-dm1\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1646124018_583_Le-logiciel-malveillant-Daxin-lie-a-la-Chine-a-cible.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>La faille affecte les produits Jira suivants\u00a0:<\/p>\n<ul>\n<li>Jira Core Server, Jira Software Server et Jira Software Data Center : Toutes les versions ant\u00e9rieures \u00e0 8.13.18, 8.14.x, 8.15.x, 8.16.x, 8.17.x, 8.18.x, 8.19.x, 8.20.x ant\u00e9rieures \u00e0 8.20. 6 et 8.21.x<\/li>\n<li>Jira Service Management Server et Jira Service Management Data Center\u00a0: toutes les versions ant\u00e9rieures \u00e0 4.13.18, 4.14.x, 4.15.x, 4.16.x, 4.17.x, 4.18.x, 4.19.x, 4.20.x ant\u00e9rieures \u00e0 4.20.6, et 4.21.x<\/li>\n<\/ul>\n<p>Les versions fixes de Jira et Jira Service Management sont 8.13.18, 8.20.6 et 8.22.0 et 4.13.18, 4.20.6 et 4.22.0.<\/p>\n<p>Atlassian a \u00e9galement not\u00e9 que la faille n&#8217;affecte les applications propri\u00e9taires et tierces que si elles sont install\u00e9es dans l&#8217;une des versions Jira ou Jira Service Management susmentionn\u00e9es et qu&#8217;elles utilisent une configuration vuln\u00e9rable.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/crowdsec-tour-d\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/04\/1650021915_454_Haskers-Gang-donne-gratuitement-le-logiciel-malveillant-ZingoStealer-a-dautres.jpg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>Il est fortement recommand\u00e9 aux utilisateurs de mettre \u00e0 jour vers l&#8217;une des versions corrig\u00e9es pour att\u00e9nuer les tentatives d&#8217;exploitation potentielles.  Si la correction imm\u00e9diate n&#8217;est pas une option, la soci\u00e9t\u00e9 conseille de mettre \u00e0 jour les applications concern\u00e9es vers une version fixe ou de les d\u00e9sactiver compl\u00e8tement.<\/p>\n<p>Il convient de noter qu&#8217;une faille critique d&#8217;ex\u00e9cution de code \u00e0 distance dans Atlassian Confluence (CVE-2021-26084, score CVSS\u00a0: 9,8) a \u00e9t\u00e9 activement militaris\u00e9e l&#8217;ann\u00e9e derni\u00e8re pour installer des mineurs de crypto-monnaie sur des serveurs compromis.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/04\/atlassian-drops-patches-for-critical.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Atlassian a publi\u00e9 un avertissement de s\u00e9curit\u00e9 concernant une vuln\u00e9rabilit\u00e9 critique dans son logiciel Jira qui pourrait \u00eatre exploit\u00e9e par un attaquant distant non authentifi\u00e9 pour contourner les protections d&#8217;authentification. Suivi comme CVE-2022-0540, la faille est not\u00e9e 9,9 sur 10 sur le syst\u00e8me de notation CVSS et r\u00e9side dans le framework d&#8217;authentification de Jira, Jira [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":106072,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[54518,4168,20618,15954,22,4158,4165,4161,133,54520,4157,4159,4171,4170,54519,4167,4160,4163,4162,185,4172,4169,1549,4166,3667,4164],"class_list":["post-106071","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-atlassian","tag-comment-pirater","tag-contournement","tag-correctifs","tag-critique","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-des","tag-jira","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-lauthentification","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-pour","tag-securite-informatique","tag-securite-internet","tag-supprime","tag-violation-de-donnees","tag-vulnerabilite","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/106071","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=106071"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/106071\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/106072"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=106071"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=106071"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=106071"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}