{"id":105840,"date":"2022-12-05T15:36:44","date_gmt":"2022-12-05T13:36:44","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-vs-code-grafana-gnu-emacs-i-apache-fineract"},"modified":"2022-12-05T15:36:44","modified_gmt":"2022-12-05T13:36:44","slug":"uyazvimosti-v-vs-code-grafana-gnu-emacs-i-apache-fineract","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimosti-v-vs-code-grafana-gnu-emacs-i-apache-fineract","title":{"rendered":"Vuln\u00e9rabilit\u00e9s dans VS Code, Grafana, GNU Emacs et Apache Fineract","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Plusieurs vuln\u00e9rabilit\u00e9s r\u00e9cemment d\u00e9couvertes :  <\/p>\n<ul>\n<li class=\"l\"> Une vuln\u00e9rabilit\u00e9 critique a \u00e9t\u00e9 identifi\u00e9e dans l'\u00e9diteur Visual Studio Code (VS Code) (CVE-2022-41034), permettant l'ex\u00e9cution de code lorsque l'utilisateur ouvre un lien pr\u00e9par\u00e9 par un attaquant. Le code peut \u00eatre ex\u00e9cut\u00e9 \u00e0 la fois sur l'ordinateur avec VS Code et sur d'autres ordinateurs connect\u00e9s \u00e0 VS Code via la fonction \u00ab Remote Development \u00bb. Ce probl\u00e8me repr\u00e9sente un danger particulier pour les utilisateurs de la version web de VS Code et des \u00e9diteurs web bas\u00e9s sur celle-ci, y compris GitHub Codespaces et github.dev.\n<p>La vuln\u00e9rabilit\u00e9 est caus\u00e9e par la possibilit\u00e9 de traiter des liens sp\u00e9cifiques \u00ab command: \u00bb pour ouvrir une fen\u00eatre de terminal et ex\u00e9cuter des commandes shell arbitraires, lors du traitement de documents sp\u00e9cialement format\u00e9s au format Jupyter Notebook, charg\u00e9s depuis <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/fr\/server\/\"   title=\"serveur web\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"765\">serveur web<\/a>, sous le contr\u00f4le de l'attaquant (les fichiers externes avec l'extension \u00ab .ipynb \u00bb s'ouvrent sans confirmation suppl\u00e9mentaire en mode \u00ab isTrusted \u00bb, permettant ainsi le traitement de \u00ab command: \u00bb).    <\/p>\n<li class=\"l\"> Une vuln\u00e9rabilit\u00e9 (CVE-2022-45939) a \u00e9t\u00e9 identifi\u00e9e dans l'\u00e9diteur de texte GNU Emacs, permettant l'ex\u00e9cution de commandes lors de l'ouverture d'un fichier de code, via la substitution de caract\u00e8res sp\u00e9ciaux dans le nom, trait\u00e9es \u00e0 l'aide de l'outil ctags.\n<li class=\"l\"> Dans la plateforme de visualisation de donn\u00e9es ouverte Grafana, une vuln\u00e9rabilit\u00e9 (CVE-2022-31097) a \u00e9t\u00e9 identifi\u00e9e, permettant l'ex\u00e9cution de code JavaScript lors de l'affichage d'une notification via le syst\u00e8me Grafana Alerting. Un attaquant disposant de droits d'\u00e9diteur (Editor) peut pr\u00e9parer un lien soigneusement format\u00e9 et acc\u00e9der \u00e0 l'interface Grafana avec des droits d'administrateur si l'administrateur suit ce lien. La vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 corrig\u00e9e dans les versions Grafana 9.2.7, 9.3.0, 9.0.3, 8.5.9, 8.4.10 et 8.3.10.\n<li class=\"l\"> Une vuln\u00e9rabilit\u00e9 (CVE-2022-46146) dans la biblioth\u00e8que exporter-toolkit, utilis\u00e9e pour cr\u00e9er des modules d'exportation de m\u00e9triques pour Prometheus. Le probl\u00e8me permet de contourner l'authentification basique.\n<li class=\"l\"> Une vuln\u00e9rabilit\u00e9 (CVE-2022-44635) dans la plateforme de services financiers Apache Fineract permet \u00e0 un utilisateur non authentifi\u00e9 d'obtenir une ex\u00e9cution de code \u00e0 distance. Ce probl\u00e8me est caus\u00e9 par l'absence de l'\u00e9chappement correct des caract\u00e8res \u00ab .. \u00bb dans les chemins trait\u00e9s par le composant de chargement de fichiers. La vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 corrig\u00e9e dans les versions Apache Fineract 1.7.1 et 1.8.1.\n<li class=\"l\"> Une vuln\u00e9rabilit\u00e9 (CVE-2022-46366) dans le framework Java Apache Tapestry, permettant l'ex\u00e9cution de code \u00e0 travers la d\u00e9s\u00e9rialisation de donn\u00e9es sp\u00e9cialement format\u00e9es. Le probl\u00e8me ne concerne que l'ancienne version Apache Tapestry 3.x, qui n'est plus support\u00e9e.\n<li class=\"l\"> Des vuln\u00e9rabilit\u00e9s dans les fournisseurs Apache Airflow vers Hive (CVE-2022-41131), Pinot (CVE-2022-38649), Pig (CVE-2022-40189) et Spark (CVE-2022-40954), entra\u00eenant l'ex\u00e9cution distante de code par le biais du t\u00e9l\u00e9chargement de fichiers arbitraires ou de la substitution de commandes dans le contexte de l'ex\u00e9cution des t\u00e2ches, sans avoir acc\u00e8s en \u00e9criture aux fichiers DAG.                <\/ul>\n<p>Source : <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=58264\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: \u0412 \u0440\u0435\u0434\u0430\u043a\u0442\u043e\u0440\u0435 Visual Studio Code (VS Code) \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-41034), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043a\u043e\u0434\u0430 \u043f\u0440\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u043c \u0441\u0441\u044b\u043b\u043a\u0438, \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u043c. \u041a\u043e\u0434 \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d \u043a\u0430\u043a \u043d\u0430 \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u0435 \u0441 VS Code, \u0442\u0430\u043a \u0438 \u043d\u0430 \u043b\u044e\u0431\u044b\u0445 \u0434\u0440\u0443\u0433\u0438\u0445 \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u0430\u0445, \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0451\u043d\u043d\u044b\u0445 \u043a VS Code \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 &#171;Remote Development&#187;. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 \u043d\u0430\u0438\u0431\u043e\u043b\u044c\u0448\u0443\u044e \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c \u0434\u043b\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-105840","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: \u0412 \u0440\u0435\u0434\u0430\u043a\u0442\u043e\u0440\u0435 Visual Studio Code (VS Code) \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-41034), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043a\u043e\u0434\u0430 \u043f\u0440\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimosti-v-vs-code-grafana-gnu-emacs-i-apache-fineract\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 VS Code, Grafana, GNU Emacs \u0438 Apache Fineract | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: \u0412 \u0440\u0435\u0434\u0430\u043a\u0442\u043e\u0440\u0435 Visual Studio Code (VS Code) \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-41034), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043a\u043e\u0434\u0430 \u043f\u0440\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimosti-v-vs-code-grafana-gnu-emacs-i-apache-fineract\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-12-05T13:36:44+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-12-05T13:36:44+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vuln\u00e9rabilit\u00e9s dans VS Code, Grafana, GNU Emacs et Apache Fineract | ProHoster","description":"Plusieurs vuln\u00e9rabilit\u00e9s r\u00e9cemment d\u00e9couvertes : Une vuln\u00e9rabilit\u00e9 critique (CVE-2022-41034) a \u00e9t\u00e9 identifi\u00e9e dans l'\u00e9diteur Visual Studio Code (VS Code), permettant l'ex\u00e9cution de code \u00e0 l'ouverture.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimosti-v-vs-code-grafana-gnu-emacs-i-apache-fineract","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 VS Code, Grafana, GNU Emacs \u0438 Apache Fineract | ProHoster","og:description":"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: \u0412 \u0440\u0435\u0434\u0430\u043a\u0442\u043e\u0440\u0435 Visual Studio Code (VS Code) \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-41034), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043a\u043e\u0434\u0430 \u043f\u0440\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u0438.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimosti-v-vs-code-grafana-gnu-emacs-i-apache-fineract","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-12-05T13:36:44+00:00","article:modified_time":"2022-12-05T13:36:44+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"105840","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-02-08 20:31:51","updated":"2026-02-08 20:31:51","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/105840","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=105840"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/105840\/revisions"}],"predecessor-version":[{"id":157956,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/105840\/revisions\/157956"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=105840"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=105840"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=105840"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}