{"id":15987,"date":"2022-03-04T08:58:50","date_gmt":"2022-03-04T10:58:50","guid":{"rendered":"https:\/\/teknomers.com\/fr\/une-nouvelle-vulnerabilite-de-securite-affecte-des-milliers-dinstances-gitlab\/"},"modified":"2022-03-04T08:59:11","modified_gmt":"2022-03-04T10:59:11","slug":"une-nouvelle-vulnerabilite-de-securite-affecte-des-milliers-dinstances-gitlab","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/une-nouvelle-vulnerabilite-de-securite-affecte-des-milliers-dinstances-gitlab\/","title":{"rendered":"Une nouvelle vuln\u00e9rabilit\u00e9 de s\u00e9curit\u00e9 affecte des milliers d&#8217;instances GitLab"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Les chercheurs ont r\u00e9v\u00e9l\u00e9 les d\u00e9tails d&#8217;une vuln\u00e9rabilit\u00e9 de s\u00e9curit\u00e9 d\u00e9sormais corrig\u00e9e dans GitLab, un logiciel DevOps open source, qui pourrait potentiellement permettre \u00e0 un attaquant distant et non authentifi\u00e9 de r\u00e9cup\u00e9rer des informations relatives \u00e0 l&#8217;utilisateur.<\/p>\n<p>Suivie comme CVE-2021-4191 (score CVSS\u00a0: 5,3), la faille de gravit\u00e9 moyenne affecte toutes les versions de GitLab Community Edition et Enterprise Edition \u00e0 partir de 13.0 et toutes les versions \u00e0 partir de 14.4 et ant\u00e9rieures \u00e0 14.8.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/backhub-d1\" target=\"_blank\" title=\"Automatic GitHub Backups\"><img loading=\"lazy\" decoding=\"async\" alt=\"Sauvegardes GitHub automatiques\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/1645701000_960_Dridex-Malware-Deploiement-Entropy-Ransomware-sur-des-ordinateurs-pirates.png\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>Jake Baines, chercheur principal en s\u00e9curit\u00e9 chez Rapid7, est cr\u00e9dit\u00e9 d&#8217;avoir d\u00e9couvert et signal\u00e9 la faille.  Suite \u00e0 la divulgation responsable du 18 novembre 2021, des correctifs ont \u00e9t\u00e9 <a rel=\"nofollow noopener\" href=\"https:\/\/about.gitlab.com\/releases\/2022\/02\/25\/critical-security-release-gitlab-14-8-2-released\/#unauthenticated-user-enumeration-on-graphql-api\" target=\"_blank\">publi\u00e9<\/a> dans le cadre des versions de s\u00e9curit\u00e9 critiques de GitLab 14.8.2, 14.7.4 et 14.6.5 livr\u00e9es le 25 f\u00e9vrier 2022.<\/p>\n<p>&#8220;La vuln\u00e9rabilit\u00e9 est le r\u00e9sultat d&#8217;une v\u00e9rification d&#8217;authentification manquante lors de l&#8217;ex\u00e9cution de certaines requ\u00eates de l&#8217;API GitLab GraphQL&#8221;, a d\u00e9clar\u00e9 Baines. <a rel=\"nofollow noopener\" href=\"https:\/\/www.rapid7.com\/blog\/post\/2022\/03\/03\/cve-2021-4191-gitlab-graphql-api-user-enumeration-fixed\/\" target=\"_blank\">mentionn\u00e9<\/a> dans un rapport publi\u00e9 jeudi.  &#8220;Un attaquant distant non authentifi\u00e9 peut utiliser cette vuln\u00e9rabilit\u00e9 pour collecter des noms d&#8217;utilisateur, des noms et des adresses e-mail GitLab enregistr\u00e9s.&#8221;<\/p>\n<div class=\"separator\" style=\"clear: both\"><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"387\" data-original-width=\"728\" src=\"https:\/\/thehackernews.com\/new-images\/img\/a\/AVvXsEiTchYgiNEghVSJO9RSnjIrR4I4nLhDcIE_TLA0Su3d3Ic1rgWlDuQko87Op-h25voP_8phzFM78htf23gLy0Y-_iZlqZLglOh7Qzr__OpReS2ZnDgXflkO1hi-sRtDvarFZ5125QnlgdpZ_h-7AQtkVJC9cTkZKcBzgw5hOAiKmUb__zzJ1oCrykgF\" \/><\/div>\n<p>L&#8217;exploitation r\u00e9ussie de la fuite d&#8217;informations de l&#8217;API pourrait permettre \u00e0 des acteurs malveillants d&#8217;\u00e9num\u00e9rer et de compiler des listes de noms d&#8217;utilisateur l\u00e9gitimes appartenant \u00e0 une cible qui peuvent ensuite \u00eatre utilis\u00e9es comme tremplin pour mener des attaques par force brute, y compris <a rel=\"nofollow noopener\" href=\"https:\/\/attack.mitre.org\/techniques\/T1110\/001\/\" target=\"_blank\">deviner le mot de passe<\/a>, <a rel=\"nofollow noopener\" href=\"https:\/\/attack.mitre.org\/techniques\/T1110\/003\/\" target=\"_blank\">pulv\u00e9risation de mot de passe<\/a>et <a rel=\"nofollow noopener\" href=\"https:\/\/attack.mitre.org\/techniques\/T1110\/004\/\" target=\"_blank\">bourrage d&#8217;informations d&#8217;identification<\/a>.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-feb-header\" target=\"_blank\" title=\"Prevent Data Breaches\"><img loading=\"lazy\" decoding=\"async\" alt=\"Emp\u00eacher les violations de donn\u00e9es\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1646326908_645_Correctifs-critiques-publies-pour-la-gamme-Cisco-Expressway-les-produits.jpeg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>&#8220;La fuite d&#8217;informations permet \u00e9galement potentiellement \u00e0 un attaquant de cr\u00e9er une nouvelle liste de mots d&#8217;utilisateur bas\u00e9e sur les installations de GitLab &#8211; non seulement \u00e0 partir de gitlab.com mais \u00e9galement \u00e0 partir des 50 000 autres instances de GitLab accessibles depuis Internet&#8221;, a d\u00e9clar\u00e9 Baines.<\/p>\n<p>Outre CVE-2021-4191, le correctif corrige \u00e9galement six autres failles de s\u00e9curit\u00e9, dont l&#8217;une est un probl\u00e8me critique (CVE-2022-0735, score CVSS\u00a0: 9,6) qui permet \u00e0 un attaquant non autoris\u00e9 de siphonner le <a rel=\"nofollow noopener\" href=\"https:\/\/docs.gitlab.com\/runner\/\" target=\"_blank\">jetons d&#8217;inscription des coureurs<\/a> utilis\u00e9 pour authentifier et autoriser les t\u00e2ches CI\/CD h\u00e9berg\u00e9es sur des instances GitLab.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/03\/new-security-vulnerability-affects.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Les chercheurs ont r\u00e9v\u00e9l\u00e9 les d\u00e9tails d&#8217;une vuln\u00e9rabilit\u00e9 de s\u00e9curit\u00e9 d\u00e9sormais corrig\u00e9e dans GitLab, un logiciel DevOps open source, qui pourrait potentiellement permettre \u00e0 un attaquant distant et non authentifi\u00e9 de r\u00e9cup\u00e9rer des informations relatives \u00e0 l&#8217;utilisateur. Suivie comme CVE-2021-4191 (score CVSS\u00a0: 5,3), la faille de gravit\u00e9 moyenne affecte toutes les versions de GitLab Community [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":15988,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[1132,4168,4158,4165,4161,133,16896,16897,4157,4159,4171,4170,4167,1558,4160,197,4163,4162,1835,4172,4169,196,4166,3667,4164],"class_list":["post-15987","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-affecte","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-des","tag-dinstances","tag-gitlab","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-logiciel-malveillant-de-ransomware","tag-milliers","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelle","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-securite","tag-securite-informatique","tag-securite-internet","tag-une","tag-violation-de-donnees","tag-vulnerabilite","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/15987","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=15987"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/15987\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/15988"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=15987"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=15987"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=15987"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}