{"id":73679,"date":"2022-04-05T23:42:40","date_gmt":"2022-04-06T01:42:40","guid":{"rendered":"https:\/\/teknomers.com\/fr\/la-cisa-met-en-garde-contre-lexploitation-active-de-la-vulnerabilite-critique-de-spring4shell\/"},"modified":"2022-04-05T23:42:44","modified_gmt":"2022-04-06T01:42:44","slug":"la-cisa-met-en-garde-contre-lexploitation-active-de-la-vulnerabilite-critique-de-spring4shell","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/la-cisa-met-en-garde-contre-lexploitation-active-de-la-vulnerabilite-critique-de-spring4shell\/","title":{"rendered":"La CISA met en garde contre l&#8217;exploitation active de la vuln\u00e9rabilit\u00e9 critique de Spring4Shell"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>L&#8217;Agence am\u00e9ricaine de cybers\u00e9curit\u00e9 et de s\u00e9curit\u00e9 des infrastructures (CISA) a ajout\u00e9 lundi la vuln\u00e9rabilit\u00e9 d&#8217;ex\u00e9cution de code \u00e0 distance (RCE) r\u00e9cemment divulgu\u00e9e affectant le Spring Framework, \u00e0 son <a rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">Catalogue des vuln\u00e9rabilit\u00e9s exploit\u00e9es connues<\/a> sur la base de &#8220;preuves d&#8217;exploitation active&#8221;.<\/p>\n<p>La faille de gravit\u00e9 critique, attribu\u00e9e \u00e0 l&#8217;identifiant CVE-2022-22965 (score CVSS\u00a0: 9,8) et surnomm\u00e9e &#8220;Spring4Shell&#8221;, affecte les applications Spring model-view-controller (MVC) et Spring WebFlux ex\u00e9cut\u00e9es sur Java Development Kit 9 et versions ult\u00e9rieures.<\/p>\n<p>&#8220;L&#8217;exploitation n\u00e9cessite un point de terminaison avec DataBinder activ\u00e9 (par exemple, une requ\u00eate POST qui d\u00e9code automatiquement les donn\u00e9es du corps de la requ\u00eate) et d\u00e9pend fortement du conteneur de servlets pour l&#8217;application&#8221;, ont not\u00e9 la semaine derni\u00e8re les chercheurs pr\u00e9toriens Anthony Weems et Dallas Kaman.<\/p>\n<p>Bien que les d\u00e9tails exacts des abus dans la nature restent flous, la soci\u00e9t\u00e9 de s\u00e9curit\u00e9 de l&#8217;information SecurityScorecard <a rel=\"nofollow noopener\" href=\"https:\/\/securityscorecard.com\/blog\/spring4shell-12-year-old-vulnerability-springs-back-to-life\" target=\"_blank\">mentionn\u00e9<\/a> &#8220;Une analyse active de cette vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 observ\u00e9e provenant des suspects habituels comme l&#8217;espace IP russe et chinois.&#8221;<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/dset1\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/Nouveau-Wiper-Malware-ciblant-lUkraine-dans-le-cadre-de-loperation.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>Des activit\u00e9s de num\u00e9risation similaires ont \u00e9t\u00e9 rep\u00e9r\u00e9es par <a rel=\"nofollow noopener\" href=\"https:\/\/www.akamai.com\/blog\/security\/spring-core-spring4shell-zero-day\" target=\"_blank\">Akama\u00ef<\/a> et Palo Alto Networks <a rel=\"nofollow noopener\" href=\"https:\/\/unit42.paloaltonetworks.com\/cve-2022-22965-springshell\/\" target=\"_blank\">Unit\u00e942<\/a>les tentatives menant au d\u00e9ploiement d&#8217;un shell Web pour l&#8217;acc\u00e8s par porte d\u00e9rob\u00e9e et \u00e0 l&#8217;ex\u00e9cution de commandes arbitraires sur le serveur dans le but de diffuser d&#8217;autres logiciels malveillants ou de se propager au sein du r\u00e9seau cible.<\/p>\n<p>Selon <a rel=\"nofollow noopener\" href=\"https:\/\/www.sonatype.com\/resources\/springshell-exploit-resource-center\" target=\"_blank\">statistiques<\/a> publi\u00e9es par Sonatype, les versions potentiellement vuln\u00e9rables du Spring Framework repr\u00e9sentent 81 % du total des t\u00e9l\u00e9chargements depuis le r\u00e9f\u00e9rentiel Maven Central depuis que le probl\u00e8me a \u00e9t\u00e9 r\u00e9v\u00e9l\u00e9 le 31 mars.<\/p>\n<p>Cisco, qui est <a rel=\"nofollow noopener\" href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-java-spring-rce-Zx9GUc67\" target=\"_blank\">enqu\u00eatant activement<\/a> son line-up pour d\u00e9terminer lequel d&#8217;entre eux pourrait \u00eatre impact\u00e9 par la vuln\u00e9rabilit\u00e9, a confirm\u00e9 que trois de ses produits sont concern\u00e9s &#8211;<\/p>\n<ul>\n<li>Moteur d&#8217;optimisation Cisco Crosswork<\/li>\n<li>Cisco Crosswork Zero Touch Provisioning (ZTP) et<\/li>\n<li>Cisco Edge Intelligence<\/li>\n<\/ul>\n<p>VMware, pour sa part, a \u00e9galement consid\u00e9r\u00e9 trois de ses produits comme vuln\u00e9rables, proposant des correctifs et des solutions de contournement le cas \u00e9ch\u00e9ant &#8211;<\/p>\n<ul>\n<li>Service d&#8217;application VMware Tanzu pour les machines virtuelles<\/li>\n<li>Gestionnaire des op\u00e9rations VMware Tanzu et<\/li>\n<li>VMware Tanzu Kubernetes Grid Integrated Edition (TKGI)<\/li>\n<\/ul>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-feb-header\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1647417170_810_Facebook-frappe-dune-amende-de-186-millions-de-dollars-GDPR.jpeg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>&#8220;Un acteur malveillant disposant d&#8217;un acc\u00e8s r\u00e9seau \u00e0 un produit VMware impact\u00e9 peut exploiter ce probl\u00e8me pour obtenir le contr\u00f4le total du syst\u00e8me cible&#8221;, explique VMware. <a rel=\"nofollow noopener\" href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2022-0010.html\" target=\"_blank\">mentionn\u00e9<\/a> dans le conseil.<\/p>\n<p>La CISA a \u00e9galement ajout\u00e9 au catalogue deux failles zero-day corrig\u00e9es par Apple la semaine derni\u00e8re (CVE-2022-22674 et CVE-2022-22675) et une lacune critique dans les routeurs D-Link (CVE-2021-45382) qui a \u00e9t\u00e9 activement militaris\u00e9 par la campagne DDoS bas\u00e9e sur Beastmode Mirai.<\/p>\n<p>Conform\u00e9ment \u00e0 la directive op\u00e9rationnelle contraignante (BOD) <a rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/binding-operational-directive-22-01\" target=\"_blank\">Publi\u00e9<\/a> par la CISA en novembre 2021, les agences du Pouvoir ex\u00e9cutif civil f\u00e9d\u00e9ral (FCEB) sont tenues de rem\u00e9dier aux vuln\u00e9rabilit\u00e9s identifi\u00e9es d&#8217;ici le 25 avril 2022.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/04\/cisa-warns-of-active-exploitation-of.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>L&#8217;Agence am\u00e9ricaine de cybers\u00e9curit\u00e9 et de s\u00e9curit\u00e9 des infrastructures (CISA) a ajout\u00e9 lundi la vuln\u00e9rabilit\u00e9 d&#8217;ex\u00e9cution de code \u00e0 distance (RCE) r\u00e9cemment divulgu\u00e9e affectant le Spring Framework, \u00e0 son Catalogue des vuln\u00e9rabilit\u00e9s exploit\u00e9es connues sur la base de &#8220;preuves d&#8217;exploitation active&#8221;. La faille de gravit\u00e9 critique, attribu\u00e9e \u00e0 l&#8217;identifiant CVE-2022-22965 (score CVSS\u00a0: 9,8) et surnomm\u00e9e [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":73680,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[9261,4805,4168,841,22,4158,4165,4161,525,4157,4159,4171,4170,14592,4167,4955,4160,4163,4162,4172,4169,43790,4166,3667,4164],"class_list":["post-73679","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-active","tag-cisa","tag-comment-pirater","tag-contre","tag-critique","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-garde","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-lexploitation","tag-logiciel-malveillant-de-ransomware","tag-met","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-securite-informatique","tag-securite-internet","tag-spring4shell","tag-violation-de-donnees","tag-vulnerabilite","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/73679","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=73679"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/73679\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/73680"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=73679"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=73679"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=73679"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}