{"id":329134,"date":"2022-08-24T06:53:25","date_gmt":"2022-08-24T08:53:25","guid":{"rendered":"https:\/\/teknomers.com\/fr\/gitlab-publie-un-correctif-pour-une-faille-critique-dans-son-logiciel-communautaire-et-dentreprise\/"},"modified":"2022-08-24T06:53:26","modified_gmt":"2022-08-24T08:53:26","slug":"gitlab-publie-un-correctif-pour-une-faille-critique-dans-son-logiciel-communautaire-et-dentreprise","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/gitlab-publie-un-correctif-pour-une-faille-critique-dans-son-logiciel-communautaire-et-dentreprise\/","title":{"rendered":"GitLab publie un correctif pour une faille critique dans son logiciel communautaire et d&#8217;entreprise"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>La plateforme DevOps GitLab a publi\u00e9 cette semaine des correctifs pour corriger une faille de s\u00e9curit\u00e9 critique dans son logiciel qui pourrait conduire \u00e0 l&#8217;ex\u00e9cution de code arbitraire sur les syst\u00e8mes concern\u00e9s.<\/p>\n<p>Suivi comme <a rel=\"nofollow noopener\" href=\"https:\/\/about.gitlab.com\/releases\/2022\/08\/22\/critical-security-release-gitlab-15-3-1-released\/\" target=\"_blank\">CVE-2022-2884<\/a>le probl\u00e8me est not\u00e9 9,9 sur le syst\u00e8me de notation des vuln\u00e9rabilit\u00e9s CVSS et affecte toutes les versions de GitLab Community Edition (CE) et Enterprise Edition (EE) \u00e0 partir de 11.3.4 avant 15.1.5, 15.2 avant 15.2.3 et 15.3 avant 15.3. 1.<\/p>\n<p>\u00c0 la base, la faiblesse de s\u00e9curit\u00e9 est un cas d&#8217;ex\u00e9cution de code \u00e0 distance authentifi\u00e9e qui peut \u00eatre d\u00e9clench\u00e9e via l&#8217;API d&#8217;importation GitHub.  GitLab cr\u00e9dit\u00e9 <a rel=\"nofollow noopener\" href=\"https:\/\/hackerone.com\/yvvdwf\" target=\"_blank\">yvvdwf<\/a> avec la d\u00e9couverte et le signalement de la faille.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/strike-d\" target=\"_blank\" title=\"DevOps backupy\"><img decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" loading=\"lazy\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/08\/Google-decouvre-un-outil-utilise-par-les-pirates-iraniens-pour.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>Bien que le probl\u00e8me ait \u00e9t\u00e9 r\u00e9solu dans les versions 15.3.1, 15.2.3, 15.1.5, les utilisateurs ont \u00e9galement la possibilit\u00e9 de se prot\u00e9ger contre la faille en d\u00e9sactivant temporairement l&#8217;option d&#8217;importation GitHub &#8211;<\/p>\n<ul>\n<li>Cliquez sur &#8220;Menu&#8221; -&gt; &#8220;Admin&#8221;<\/li>\n<li>Cliquez sur &#8220;Param\u00e8tres&#8221; -&gt; &#8220;G\u00e9n\u00e9ral&#8221;<\/li>\n<li>D\u00e9veloppez l&#8217;onglet &#8220;Visibilit\u00e9 et contr\u00f4les d&#8217;acc\u00e8s&#8221;<\/li>\n<li>Sous &#8220;Importer des sources&#8221;, d\u00e9sactivez l&#8217;option &#8220;GitHub&#8221;<\/li>\n<li>Cliquez sur &#8220;Enregistrer les modifications&#8221;<\/li>\n<\/ul>\n<p>Il n&#8217;y a aucune preuve que le probl\u00e8me soit exploit\u00e9 dans des attaques dans la nature.  Cela dit, il est recommand\u00e9 aux utilisateurs ex\u00e9cutant une installation affect\u00e9e de mettre \u00e0 jour vers la derni\u00e8re version d\u00e8s que possible.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/08\/gitlab-issues-patch-for-critical-flaw.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>La plateforme DevOps GitLab a publi\u00e9 cette semaine des correctifs pour corriger une faille de s\u00e9curit\u00e9 critique dans son logiciel qui pourrait conduire \u00e0 l&#8217;ex\u00e9cution de code arbitraire sur les syst\u00e8mes concern\u00e9s. Suivi comme CVE-2022-2884le probl\u00e8me est not\u00e9 9,9 sur le syst\u00e8me de notation des vuln\u00e9rabilit\u00e9s CVSS et affecte toutes les versions de GitLab Community [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":329135,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[4168,15808,32471,22,4158,4165,4161,429,3482,9048,16897,4157,4159,4171,4170,6816,4167,4160,4163,4162,185,2212,4172,4169,167,196,4166,4164],"class_list":["post-329134","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-comment-pirater","tag-communautaire","tag-correctif","tag-critique","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-dans","tag-dentreprise","tag-faille","tag-gitlab","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-logiciel","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-pour","tag-publie","tag-securite-informatique","tag-securite-internet","tag-son","tag-une","tag-violation-de-donnees","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/329134","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=329134"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/329134\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/329135"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=329134"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=329134"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=329134"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}