{"id":63513,"date":"2022-03-31T05:00:30","date_gmt":"2022-03-31T07:00:30","guid":{"rendered":"https:\/\/teknomers.com\/fr\/le-bogue-rce-de-0-jour-de-java-spring-framework-non-corrige-menace-la-securite-des-applications-web-dentreprise\/"},"modified":"2022-03-31T05:00:37","modified_gmt":"2022-03-31T07:00:37","slug":"le-bogue-rce-de-0-jour-de-java-spring-framework-non-corrige-menace-la-securite-des-applications-web-dentreprise","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/le-bogue-rce-de-0-jour-de-java-spring-framework-non-corrige-menace-la-securite-des-applications-web-dentreprise\/","title":{"rendered":"Le bogue RCE de 0 jour de Java Spring Framework non corrig\u00e9 menace la s\u00e9curit\u00e9 des applications Web d&#8217;entreprise"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Une vuln\u00e9rabilit\u00e9 d&#8217;ex\u00e9cution de code \u00e0 distance (RCE) zero-day a \u00e9t\u00e9 d\u00e9couverte dans le framework Spring peu de temps apr\u00e8s qu&#8217;un chercheur chinois en s\u00e9curit\u00e9 <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/vxunderground\/status\/1509170582469943303\" target=\"_blank\">bri\u00e8vement divulgu\u00e9<\/a> une <a rel=\"nofollow noopener\" href=\"https:\/\/github.com\/tweedge\/springcore-0day-en\" target=\"_blank\">preuve de concept<\/a> (PoC) <a rel=\"nofollow noopener\" href=\"https:\/\/www.rapid7.com\/blog\/post\/2022\/03\/30\/spring4shell-zero-day-vulnerability-in-spring-framework\/\" target=\"_blank\">exploit<\/a> sur GitHub avant de supprimer leur compte.<\/p>\n<p>Selon la soci\u00e9t\u00e9 de cybers\u00e9curit\u00e9 Praetorian, la faille non corrig\u00e9e affecte Spring Core sur Java Development Kit (<a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/Java_Development_Kit\" target=\"_blank\">JDK<\/a>) versions 9 et ult\u00e9rieures et est un contournement pour une autre vuln\u00e9rabilit\u00e9 suivie comme <a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2010-1622\" target=\"_blank\">CVE-2010-1622<\/a>permettant \u00e0 un attaquant non authentifi\u00e9 d&#8217;ex\u00e9cuter du code arbitraire sur le syst\u00e8me cible.<\/p>\n<p>Le printemps est un <a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/Spring_Framework\" target=\"_blank\">cadre logiciel<\/a> pour cr\u00e9er des applications Java, y compris des applications Web sur la plate-forme Java EE (Enterprise Edition).<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/backhub-d1\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/1645701000_960_Dridex-Malware-Deploiement-Entropy-Ransomware-sur-des-ordinateurs-pirates.png\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>&#8220;Dans certaines configurations, l&#8217;exploitation de ce probl\u00e8me est simple, car il suffit qu&#8217;un attaquant envoie une requ\u00eate HTTP sp\u00e9cialement con\u00e7ue \u00e0 un syst\u00e8me vuln\u00e9rable&#8221;, ont d\u00e9clar\u00e9 les chercheurs Anthony Weems et Dallas Kaman. <a rel=\"nofollow noopener\" href=\"https:\/\/www.praetorian.com\/blog\/spring-core-jdk9-rce\/\" target=\"_blank\">mentionn\u00e9<\/a>.  &#8220;Cependant, l&#8217;exploitation de diff\u00e9rentes configurations obligera l&#8217;attaquant \u00e0 effectuer des recherches suppl\u00e9mentaires pour trouver des charges utiles qui seront efficaces.&#8221;<\/p>\n<p>D\u00e9tails suppl\u00e9mentaires de la faille, surnomm\u00e9s &#8220;<strong>SpringShell<\/strong>&#8221; et &#8220;<strong>Spring4Shell<\/strong>&#8220;, ont \u00e9t\u00e9 retenus pour emp\u00eacher les tentatives d&#8217;exploitation et jusqu&#8217;\u00e0 ce qu&#8217;un correctif soit mis en place par les responsables du framework, Spring.io, une filiale de VMware. Il n&#8217;a pas non plus encore re\u00e7u d&#8217;identifiant CVE (Common Vulnerabilities and Exposures).<\/p>\n<p>Il convient de noter que la faille cibl\u00e9e par l&#8217;exploit zero-day est diff\u00e9rente des deux vuln\u00e9rabilit\u00e9s pr\u00e9c\u00e9dentes divulgu\u00e9es dans le cadre de l&#8217;application cette semaine, y compris la vuln\u00e9rabilit\u00e9 DoS de l&#8217;expression Spring Framework (<a rel=\"nofollow noopener\" href=\"https:\/\/tanzu.vmware.com\/security\/cve-2022-22950\" target=\"_blank\">CVE-2022-22950<\/a>) et la vuln\u00e9rabilit\u00e9 d&#8217;acc\u00e8s aux ressources d&#8217;expression Spring Cloud (<a rel=\"nofollow noopener\" href=\"https:\/\/tanzu.vmware.com\/security\/cve-2022-22963\" target=\"_blank\">CVE-2022-22963<\/a>).<\/p>\n<div class=\"separator\" style=\"clear: both\"><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"500\" data-original-width=\"728\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1648710030_806_Le-bogue-RCE-de-0-jour-de-Java-Spring-Framework.jpg\" \/><\/div>\n<p>Dans l&#8217;intervalle, la soci\u00e9t\u00e9 recommande &#8220;de cr\u00e9er un composant ControllerAdvice (qui est un composant Spring partag\u00e9 entre les contr\u00f4leurs) et d&#8217;ajouter des mod\u00e8les dangereux \u00e0 la liste de refus&#8221;.<\/p>\n<p>L&#8217;analyse initiale de la nouvelle faille d&#8217;ex\u00e9cution de code dans Spring Core sugg\u00e8re que son impact pourrait ne pas \u00eatre grave.  &#8220;[C]Les informations actuelles sugg\u00e8rent que pour exploiter la vuln\u00e9rabilit\u00e9, les attaquants devront localiser et identifier les instances d&#8217;applications Web qui utilisent r\u00e9ellement DeserializationUtils, ce que les d\u00e9veloppeurs savent d\u00e9j\u00e0 \u00eatre dangereux&#8221;, Flashpoint <a rel=\"nofollow noopener\" href=\"https:\/\/www.flashpoint-intel.com\/blog\/what-is-springshell-what-we-know-about-the-springshell-vulnerability\/\" target=\"_blank\">mentionn\u00e9<\/a> dans une analyse ind\u00e9pendante.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-feb-header\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1647417170_810_Facebook-frappe-dune-amende-de-186-millions-de-dollars-GDPR.jpeg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>Malgr\u00e9 la disponibilit\u00e9 publique des exploits PoC, &#8220;il est actuellement difficile de savoir quelles applications du monde r\u00e9el utilisent la fonctionnalit\u00e9 vuln\u00e9rable&#8221;, Rapid7 <a rel=\"nofollow noopener\" href=\"https:\/\/www.rapid7.com\/blog\/post\/2022\/03\/30\/spring4shell-zero-day-vulnerability-in-spring-framework\/\" target=\"_blank\">expliqu\u00e9<\/a>.  &#8220;La configuration et la version JRE peuvent \u00e9galement \u00eatre des facteurs importants d&#8217;exploitabilit\u00e9 et de probabilit\u00e9 d&#8217;exploitation g\u00e9n\u00e9ralis\u00e9e.&#8221;<\/p>\n<p>Le Centre de partage et d&#8217;analyse d&#8217;informations sur le commerce de d\u00e9tail et l&#8217;h\u00f4tellerie (ISAC) <a rel=\"nofollow noopener\" href=\"https:\/\/www.rhisac.org\/press-release\/spring-framework-rce-vulnerability\/\" target=\"_blank\">a publi\u00e9 une d\u00e9claration<\/a> qu&#8217;il a enqu\u00eat\u00e9 et confirm\u00e9 la &#8220;validit\u00e9&#8221; du PoC pour la faille RCE, ajoutant qu&#8217;il &#8220;poursuivait les tests pour confirmer la validit\u00e9 du PoC&#8221;.<\/p>\n<p>&#8220;L&#8217;exploit Spring4Shell dans la nature semble fonctionner contre l&#8217;exemple de code stock &#8216;Handling Form Submission&#8217; de spring.io&#8221;, analyste de vuln\u00e9rabilit\u00e9 CERT\/CC Will Dormann <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/wdormann\/status\/1509372145394200579\" target=\"_blank\">mentionn\u00e9<\/a> dans un tweet.  &#8220;Si l&#8217;exemple de code est vuln\u00e9rable, alors je soup\u00e7onne qu&#8217;il existe effectivement des applications du monde r\u00e9el qui sont vuln\u00e9rables au RCE.&#8221;<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/03\/unpatched-java-spring-framework-0-day.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Une vuln\u00e9rabilit\u00e9 d&#8217;ex\u00e9cution de code \u00e0 distance (RCE) zero-day a \u00e9t\u00e9 d\u00e9couverte dans le framework Spring peu de temps apr\u00e8s qu&#8217;un chercheur chinois en s\u00e9curit\u00e9 bri\u00e8vement divulgu\u00e9 une preuve de concept (PoC) exploit sur GitHub avant de supprimer leur compte. Selon la soci\u00e9t\u00e9 de cybers\u00e9curit\u00e9 Praetorian, la faille non corrig\u00e9e affecte Spring Core sur Java [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":63514,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[8361,6813,4168,6815,4158,4165,4161,3482,133,39961,4312,3995,4157,4159,4171,4170,4167,596,4160,4163,4162,22778,1835,4172,4169,13283,4166,4164,2784],"class_list":["post-63513","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-applications","tag-bogue","tag-comment-pirater","tag-corrige","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-dentreprise","tag-des","tag-framework","tag-java","tag-jour","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-logiciel-malveillant-de-ransomware","tag-menace","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-rce","tag-securite","tag-securite-informatique","tag-securite-internet","tag-spring","tag-violation-de-donnees","tag-vulnerabilite-logicielle","tag-web"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/63513","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=63513"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/63513\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/63514"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=63513"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=63513"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=63513"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}