News: 2023-03-17T06_38_18Z

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

OnlyOffice Docs 7.3.3 soigne la sécurité : une mise à jour importante

(2023/03/17)


OnlyOffice Docs 7.3.3 soigne la sécurité : une mise à jour importante

vendredi 17 mars 2023

Quelques semaines après la sortie de la [1]version 7.3 , la suite bureautique européenne soigne sa monture, mais corrige une importante vulnérabilité. La mise à jour est jugée critique.

Dans ce correctif, les développeurs d’OnlyOffice ont éliminé de nombreux bogues (comme on peut le voir [2]sur Github ) et corrigé la vulnérabilité [3]CVE-2022-47412 récemment découverte. La correction est faite à tous les niveaux, y compris pour les clients de bureau sous Windows, Linux et macOS.

Pourquoi est-ce important ? CVE-2022-47412 est une vulnérabilité XSS Multiple DMS qui permet de récupérer des informations sur le client de l’utilisateur ciblé. L’impact possible peut être l ’usurpation de l’identité d’un utilisateur privilégié dans le portail de l’organisation en volant le cookie de session de l’utilisateur ou en exécutant des commandes personnalisées au nom de la victime en accrochant son navigateur.

L’éditeur Ascensio rappelle que la soumission des vulnérabilités à l’équipe de sécurité se fait par le biais du programme [4]HackerOne .

[5]



[1] https://www.toolinux.com/?onlyoffice-nouvelle-version

[2] https://github.com/ONLYOFFICE/DocumentServer/blob/master/CHANGELOG.md#733

[3] https://www.rapid7.com/blog/post/2023/02/07/multiple-dms-xss-cve-2022-47412-through-cve-20222-47419/

[4] https://www.onlyoffice.com/blog/2022/02/onlyoffice-is-launching-a-bounty-program-on-hackerone/

[5] https://www.toolinux.com/?onlyoffice-docs-7-3-3-soigne-la-securite-une-mise-a-jour-importante#forum



A MODERN FABLE

Aesop's fables and other traditional children's stories involve allegory
far too subtle for the youth of today. Children need an updated message
with contemporary circumstance and plot line, and short enough to suit
today's minute attention span.

The Troubled Aardvark

Once upon a time, there was an aardvark whose only pleasure in life was
driving from his suburban bungalow to his job at a large brokerage house
in his brand new 4x4. He hated his manipulative boss, his conniving and
unethical co-workers, his greedy wife, and his snivelling, spoiled
children. One day, the aardvark reflected on the meaning of his life and
his career and on the unchecked, catastrophic decline of his nation, its
pathetic excuse for leadership, and the complete ineffectiveness of any
personal effort he could make to change the status quo. Overcome by a
wave of utter depression and self-doubt, he decided to take the only
course of action that would bring him greater comfort and happiness: he
drove to the mall and bought imported consumer electronics goods.

MORAL OF THE STORY: Invest in foreign consumer electronics manufacturers.
-- Tom Annau