{"id":67606,"date":"2022-04-02T08:19:06","date_gmt":"2022-04-02T10:19:06","guid":{"rendered":"https:\/\/teknomers.com\/fr\/gitlab-publie-un-correctif-pour-une-vulnerabilite-critique-qui-pourrait-permettre-aux-attaquants-de-detourner-des-comptes\/"},"modified":"2022-04-02T08:19:13","modified_gmt":"2022-04-02T10:19:13","slug":"gitlab-publie-un-correctif-pour-une-vulnerabilite-critique-qui-pourrait-permettre-aux-attaquants-de-detourner-des-comptes","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/gitlab-publie-un-correctif-pour-une-vulnerabilite-critique-qui-pourrait-permettre-aux-attaquants-de-detourner-des-comptes\/","title":{"rendered":"GitLab publie un correctif pour une vuln\u00e9rabilit\u00e9 critique qui pourrait permettre aux attaquants de d\u00e9tourner des comptes"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>La plate-forme DevOps GitLab a publi\u00e9 des mises \u00e0 jour logicielles pour r\u00e9soudre une vuln\u00e9rabilit\u00e9 de s\u00e9curit\u00e9 critique qui, si elle \u00e9tait potentiellement exploit\u00e9e, pourrait permettre \u00e0 un adversaire de prendre le contr\u00f4le des comptes.<\/p>\n<p>Suivi comme <strong>CVE-2022-1162<\/strong>le probl\u00e8me a un score CVSS de 9,1 et aurait \u00e9t\u00e9 d\u00e9couvert en interne par l&#8217;\u00e9quipe GitLab.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/backhub-dm1\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1646124018_583_Le-logiciel-malveillant-Daxin-lie-a-la-Chine-a-cible.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>&#8220;Un mot de passe cod\u00e9 en dur a \u00e9t\u00e9 d\u00e9fini pour les comptes enregistr\u00e9s \u00e0 l&#8217;aide d&#8217;un <a rel=\"nofollow noopener\" href=\"https:\/\/github.com\/omniauth\/omniauth\" target=\"_blank\">Fournisseur OmniAuth<\/a> (par exemple, OAuth, LDAP, SAML) dans GitLab CE\/EE versions 14.7 ant\u00e9rieures \u00e0 14.7.7, 14.8 ant\u00e9rieures \u00e0 14.8.5 et 14.9 ant\u00e9rieures \u00e0 14.9.2, permettant aux attaquants de prendre potentiellement le contr\u00f4le de comptes \u00bb, la soci\u00e9t\u00e9 <a rel=\"nofollow noopener\" href=\"https:\/\/about.gitlab.com\/releases\/2022\/03\/31\/critical-security-release-gitlab-14-9-2-released\/\" target=\"_blank\">mentionn\u00e9<\/a> dans un avis publi\u00e9 le 31 mars.<\/p>\n<p>GitLab, qui a r\u00e9solu le bogue avec la derni\u00e8re version des versions 14.9.2, 14.8.5 et 14.7.7 pour GitLab Community Edition (CE) et Enterprise Edition (EE), a \u00e9galement d\u00e9clar\u00e9 avoir pris l&#8217;initiative de r\u00e9initialiser le mot de passe de un nombre ind\u00e9termin\u00e9 d&#8217;utilisateurs par prudence.<\/p>\n<div class=\"separator\" style=\"clear: both\"><img decoding=\"async\" alt=\"Vuln\u00e9rabilit\u00e9 critique GitLab\" border=\"0\" data-original-height=\"649\" data-original-width=\"728\" src=\"https:\/\/thehackernews.com\/new-images\/img\/b\/R29vZ2xl\/AVvXsEjIJ_f6WspoIxVTgw6_Rc5WZE04Hx6Zhf4Sgr24ipzICQQBeErm5YAbCRLchjGS48US-rvTWtQg5URgsJK6XcimFL2apaK4otVF76wsxNKq43sEoSuQGuFqr4VsXmkd42XGZNl6RvEVS8KsceiJ_i3-0-xn-oPLntfj-K9p1N_O5uLB7O02bUv7VgtI\/s728-e1000\/password.jpg\" title=\"Vuln\u00e9rabilit\u00e9 critique GitLab\" \/><\/div>\n<p>&#8220;Notre enqu\u00eate ne montre aucune indication que des utilisateurs ou des comptes ont \u00e9t\u00e9 compromis&#8221;, a-t-il ajout\u00e9.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-feb-header\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1647417170_810_Facebook-frappe-dune-amende-de-186-millions-de-dollars-GDPR.jpeg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>La soci\u00e9t\u00e9 a \u00e9galement <a rel=\"nofollow noopener\" href=\"https:\/\/about.gitlab.com\/releases\/2022\/03\/31\/critical-security-release-gitlab-14-9-2-released\/#script-to-identify-users-potentially-impacted-by-cve-2022-1162\" target=\"_blank\">publi\u00e9 un sc\u00e9nario<\/a> que les administrateurs d&#8217;instances autog\u00e9r\u00e9es peuvent ex\u00e9cuter pour distinguer les comptes potentiellement impact\u00e9s par CVE-2022-1162.  Une fois les comptes concern\u00e9s identifi\u00e9s, une r\u00e9initialisation du mot de passe a \u00e9t\u00e9 conseill\u00e9e.<\/p>\n<p>GitLab a \u00e9galement abord\u00e9 dans le cadre de la mise \u00e0 jour de s\u00e9curit\u00e9 deux bogues de script intersite stock\u00e9 (XSS) de haute gravit\u00e9 (CVE-2022-1175 et CVE-2022-1190) ainsi que neuf failles de gravit\u00e9 moyenne et cinq probl\u00e8mes qui sont class\u00e9 faible en gravit\u00e9.<\/p>\n<p>Compte tenu de la gravit\u00e9 de certains des probl\u00e8mes, il est fortement recommand\u00e9 aux utilisateurs ex\u00e9cutant des installations concern\u00e9es de mettre \u00e0 niveau vers la derni\u00e8re version d\u00e8s que possible.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/04\/gitlab-releases-patch-for-critical.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>La plate-forme DevOps GitLab a publi\u00e9 des mises \u00e0 jour logicielles pour r\u00e9soudre une vuln\u00e9rabilit\u00e9 de s\u00e9curit\u00e9 critique qui, si elle \u00e9tait potentiellement exploit\u00e9e, pourrait permettre \u00e0 un adversaire de prendre le contr\u00f4le des comptes. Suivi comme CVE-2022-1162le probl\u00e8me a un score CVSS de 9,1 et aurait \u00e9t\u00e9 d\u00e9couvert en interne par l&#8217;\u00e9quipe GitLab. &#8220;Un [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":67607,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[11865,507,4168,4493,32471,22,4158,4165,4161,133,31219,16897,4157,4159,4171,4170,4167,4160,4163,4162,5848,185,2102,2212,364,4172,4169,196,4166,3667,4164],"class_list":["post-67606","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-attaquants","tag-aux","tag-comment-pirater","tag-comptes","tag-correctif","tag-critique","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-des","tag-detourner","tag-gitlab","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-permettre","tag-pour","tag-pourrait","tag-publie","tag-qui","tag-securite-informatique","tag-securite-internet","tag-une","tag-violation-de-donnees","tag-vulnerabilite","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/67606","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=67606"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/67606\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/67607"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=67606"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=67606"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=67606"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}