{"id":309531,"date":"2022-01-21T08:00:00","date_gmt":"2022-01-21T13:00:00","guid":{"rendered":"https:\/\/www.actionti.com\/?p=309531"},"modified":"2022-01-20T11:22:08","modified_gmt":"2022-01-20T16:22:08","slug":"h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees","status":"publish","type":"post","link":"https:\/\/actionti.com\/en\/publications\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\/","title":{"rendered":"H2 SQL | Vuln\u00e9rabilit\u00e9 critique dans la console de base de donn\u00e9es"},"content":{"rendered":"\n<p>par Jean-Luc Doumont \u2013 Doumont 360 (Relations publiques et gestion de crise)<\/p>\n\n\n\n<p><strong>Les administrateurs informatiques disposant de la base de donn\u00e9es H2 SQL (open source) bas\u00e9e sur Java dans leurs environnements sont invit\u00e9s \u00e0 mettre \u00e0 jour vers la derni\u00e8re version apr\u00e8s la d\u00e9couverte d&#8217;une vuln\u00e9rabilit\u00e9 \u00ab&nbsp;extr\u00eamement critique&nbsp;\u00bb dans sa console.<\/strong><\/p>\n\n\n\n<p>Les chercheurs de JFrog ont&nbsp;d\u00e9clar\u00e9 que la vuln\u00e9rabilit\u00e9 &#8211;&nbsp;CVE-2021-42392 &#8211;&nbsp;a la m\u00eame cause fondamentale que la vuln\u00e9rabilit\u00e9&nbsp;Log4Shell&nbsp;dans Apache Log4j2 : une faille dans l&#8217;interface Java Naming and Directory (JDNI) qui pourrait permettre un acc\u00e8s de contr\u00f4le \u00e0 distance non authentifi\u00e9.&nbsp;Dans ce cas, il s&#8217;agit de la console de base de donn\u00e9es H2.<\/p>\n\n\n\n<p>L&#8217;alerte recommande aux administrateurs informatiques de mettre imm\u00e9diatement \u00e0 jour vers la derni\u00e8re version de H2, la version 2.0.206.&nbsp;Les impl\u00e9mentations qui exposent une console H2 \u00e0 un r\u00e9seau local ou \u00e9tendu courent un grand risque.<\/p>\n\n\n\n<p>L&#8217;alerte note \u00e9galement que certains outils de d\u00e9veloppement d&#8217;applications utilisent des bases de donn\u00e9es H2 qui exposent la console H2.&nbsp;Ces outils pourraient risquer de propager des logiciels malveillants par le biais d&#8217;attaques, avertissent les chercheurs, une autre raison pour laquelle leurs bases de donn\u00e9es devraient \u00eatre mises \u00e0 jour.<\/p>\n\n\n\n<p>Les chercheurs ajoutent que la vuln\u00e9rabilit\u00e9 dans H2 ne devrait pas \u00eatre aussi r\u00e9pandue que Log4Shell, car contrairement \u00e0 ce dernier, cette vuln\u00e9rabilit\u00e9 a un impact \u00ab direct \u00bb.&nbsp;Cela signifie que g\u00e9n\u00e9ralement le serveur qui traite la demande initiale (la console H2) sera le serveur qui sera impact\u00e9 par RCE.&nbsp;Ceci est moins grave par rapport \u00e0 Log4Shell, car les serveurs vuln\u00e9rables devraient \u00eatre plus faciles \u00e0 trouver.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>par Jean-Luc Doumont \u2013 Doumont 360 (Relations publiques et gestion de crise) Les administrateurs [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":309532,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[228],"class_list":["post-309531","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-non-classifiee-2"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>H2 SQL | Vuln\u00e9rabilit\u00e9 critique dans la console de base de donn\u00e9es | R\u00e9seau Action TI<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/actionti.com\/publications\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"H2 SQL | Vuln\u00e9rabilit\u00e9 critique dans la console de base de donn\u00e9es | R\u00e9seau Action TI\" \/>\n<meta property=\"og:description\" content=\"par Jean-Luc Doumont \u2013 Doumont 360 (Relations publiques et gestion de crise) Les administrateurs [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/actionti.com\/publications\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\/\" \/>\n<meta property=\"og:site_name\" content=\"R\u00e9seau Action TI\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/Doumont360\" \/>\n<meta property=\"article:published_time\" content=\"2022-01-21T13:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/actionti.com\/wp-content\/uploads\/2022\/01\/programming-1873854_960_720.png\" \/>\n\t<meta property=\"og:image:width\" content=\"960\" \/>\n\t<meta property=\"og:image:height\" content=\"527\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Jean-Luc Doumont\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@jldoumont\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jean-Luc Doumont\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/actionti.com\\\/publications\\\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/actionti.com\\\/publications\\\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\\\/\"},\"author\":{\"name\":\"Jean-Luc Doumont\",\"@id\":\"https:\\\/\\\/actionti.com\\\/#\\\/schema\\\/person\\\/70c2526e4d475a65b25b1596ff208e53\"},\"headline\":\"H2 SQL | Vuln\u00e9rabilit\u00e9 critique dans la console de base de donn\u00e9es\",\"datePublished\":\"2022-01-21T13:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/actionti.com\\\/publications\\\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\\\/\"},\"wordCount\":314,\"publisher\":{\"@id\":\"https:\\\/\\\/actionti.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/actionti.com\\\/publications\\\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/actionti.com\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/programming-1873854_960_720.png\",\"articleSection\":[\"Non classifi\u00e9(e)\"],\"inLanguage\":\"en-CA\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/actionti.com\\\/publications\\\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\\\/\",\"url\":\"https:\\\/\\\/actionti.com\\\/publications\\\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\\\/\",\"name\":\"H2 SQL | Vuln\u00e9rabilit\u00e9 critique dans la console de base de donn\u00e9es | R\u00e9seau Action TI\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/actionti.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/actionti.com\\\/publications\\\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/actionti.com\\\/publications\\\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/actionti.com\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/programming-1873854_960_720.png\",\"datePublished\":\"2022-01-21T13:00:00+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/actionti.com\\\/publications\\\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\\\/#breadcrumb\"},\"inLanguage\":\"en-CA\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/actionti.com\\\/publications\\\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-CA\",\"@id\":\"https:\\\/\\\/actionti.com\\\/publications\\\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\\\/#primaryimage\",\"url\":\"https:\\\/\\\/actionti.com\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/programming-1873854_960_720.png\",\"contentUrl\":\"https:\\\/\\\/actionti.com\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/programming-1873854_960_720.png\",\"width\":960,\"height\":527},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/actionti.com\\\/publications\\\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/actionti.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"H2 SQL | Vuln\u00e9rabilit\u00e9 critique dans la console de base de donn\u00e9es\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/actionti.com\\\/#website\",\"url\":\"https:\\\/\\\/actionti.com\\\/\",\"name\":\"R\u00e9seau Action TI\",\"description\":\"Regroupement des professionnels en technologies de l\u2019information (TI)\",\"publisher\":{\"@id\":\"https:\\\/\\\/actionti.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/actionti.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-CA\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/actionti.com\\\/#organization\",\"name\":\"R\u00e9seau Action TI\",\"url\":\"https:\\\/\\\/actionti.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-CA\",\"@id\":\"https:\\\/\\\/actionti.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"http:\\\/\\\/actionti.com\\\/wp-content\\\/uploads\\\/2021\\\/01\\\/Action-TI-RGB-2-couleurs.png\",\"contentUrl\":\"http:\\\/\\\/actionti.com\\\/wp-content\\\/uploads\\\/2021\\\/01\\\/Action-TI-RGB-2-couleurs.png\",\"width\":4501,\"height\":4501,\"caption\":\"R\u00e9seau Action TI\"},\"image\":{\"@id\":\"https:\\\/\\\/actionti.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/actionti.com\\\/#\\\/schema\\\/person\\\/70c2526e4d475a65b25b1596ff208e53\",\"name\":\"Jean-Luc Doumont\",\"description\":\"Strat\u00e8ge communications chez Doumont360.\",\"sameAs\":[\"http:\\\/\\\/doumont360.com\",\"https:\\\/\\\/www.facebook.com\\\/Doumont360\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/doumont360\",\"https:\\\/\\\/x.com\\\/jldoumont\"],\"url\":\"https:\\\/\\\/actionti.com\\\/en\\\/publications\\\/author\\\/jldoumont\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"H2 SQL | Vuln\u00e9rabilit\u00e9 critique dans la console de base de donn\u00e9es | R\u00e9seau Action TI","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/actionti.com\/publications\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\/","og_locale":"en_US","og_type":"article","og_title":"H2 SQL | Vuln\u00e9rabilit\u00e9 critique dans la console de base de donn\u00e9es | R\u00e9seau Action TI","og_description":"par Jean-Luc Doumont \u2013 Doumont 360 (Relations publiques et gestion de crise) Les administrateurs [&hellip;]","og_url":"https:\/\/actionti.com\/publications\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\/","og_site_name":"R\u00e9seau Action TI","article_author":"https:\/\/www.facebook.com\/Doumont360","article_published_time":"2022-01-21T13:00:00+00:00","og_image":[{"width":960,"height":527,"url":"https:\/\/actionti.com\/wp-content\/uploads\/2022\/01\/programming-1873854_960_720.png","type":"image\/png"}],"author":"Jean-Luc Doumont","twitter_card":"summary_large_image","twitter_creator":"@jldoumont","twitter_misc":{"Written by":"Jean-Luc Doumont","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/actionti.com\/publications\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\/#article","isPartOf":{"@id":"https:\/\/actionti.com\/publications\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\/"},"author":{"name":"Jean-Luc Doumont","@id":"https:\/\/actionti.com\/#\/schema\/person\/70c2526e4d475a65b25b1596ff208e53"},"headline":"H2 SQL | Vuln\u00e9rabilit\u00e9 critique dans la console de base de donn\u00e9es","datePublished":"2022-01-21T13:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/actionti.com\/publications\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\/"},"wordCount":314,"publisher":{"@id":"https:\/\/actionti.com\/#organization"},"image":{"@id":"https:\/\/actionti.com\/publications\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\/#primaryimage"},"thumbnailUrl":"https:\/\/actionti.com\/wp-content\/uploads\/2022\/01\/programming-1873854_960_720.png","articleSection":["Non classifi\u00e9(e)"],"inLanguage":"en-CA"},{"@type":"WebPage","@id":"https:\/\/actionti.com\/publications\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\/","url":"https:\/\/actionti.com\/publications\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\/","name":"H2 SQL | Vuln\u00e9rabilit\u00e9 critique dans la console de base de donn\u00e9es | R\u00e9seau Action TI","isPartOf":{"@id":"https:\/\/actionti.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/actionti.com\/publications\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\/#primaryimage"},"image":{"@id":"https:\/\/actionti.com\/publications\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\/#primaryimage"},"thumbnailUrl":"https:\/\/actionti.com\/wp-content\/uploads\/2022\/01\/programming-1873854_960_720.png","datePublished":"2022-01-21T13:00:00+00:00","breadcrumb":{"@id":"https:\/\/actionti.com\/publications\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\/#breadcrumb"},"inLanguage":"en-CA","potentialAction":[{"@type":"ReadAction","target":["https:\/\/actionti.com\/publications\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\/"]}]},{"@type":"ImageObject","inLanguage":"en-CA","@id":"https:\/\/actionti.com\/publications\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\/#primaryimage","url":"https:\/\/actionti.com\/wp-content\/uploads\/2022\/01\/programming-1873854_960_720.png","contentUrl":"https:\/\/actionti.com\/wp-content\/uploads\/2022\/01\/programming-1873854_960_720.png","width":960,"height":527},{"@type":"BreadcrumbList","@id":"https:\/\/actionti.com\/publications\/h2-sql-vulnerabilite-critique-dans-la-console-de-base-de-donnees\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/actionti.com\/en\/"},{"@type":"ListItem","position":2,"name":"H2 SQL | Vuln\u00e9rabilit\u00e9 critique dans la console de base de donn\u00e9es"}]},{"@type":"WebSite","@id":"https:\/\/actionti.com\/#website","url":"https:\/\/actionti.com\/","name":"R\u00e9seau Action TI","description":"Regroupement des professionnels en technologies de l\u2019information (TI)","publisher":{"@id":"https:\/\/actionti.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/actionti.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-CA"},{"@type":"Organization","@id":"https:\/\/actionti.com\/#organization","name":"R\u00e9seau Action TI","url":"https:\/\/actionti.com\/","logo":{"@type":"ImageObject","inLanguage":"en-CA","@id":"https:\/\/actionti.com\/#\/schema\/logo\/image\/","url":"http:\/\/actionti.com\/wp-content\/uploads\/2021\/01\/Action-TI-RGB-2-couleurs.png","contentUrl":"http:\/\/actionti.com\/wp-content\/uploads\/2021\/01\/Action-TI-RGB-2-couleurs.png","width":4501,"height":4501,"caption":"R\u00e9seau Action TI"},"image":{"@id":"https:\/\/actionti.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/actionti.com\/#\/schema\/person\/70c2526e4d475a65b25b1596ff208e53","name":"Jean-Luc Doumont","description":"Strat\u00e8ge communications chez Doumont360.","sameAs":["http:\/\/doumont360.com","https:\/\/www.facebook.com\/Doumont360","https:\/\/www.linkedin.com\/company\/doumont360","https:\/\/x.com\/jldoumont"],"url":"https:\/\/actionti.com\/en\/publications\/author\/jldoumont\/"}]}},"_links":{"self":[{"href":"https:\/\/actionti.com\/en\/wp-json\/wp\/v2\/posts\/309531","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/actionti.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/actionti.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/actionti.com\/en\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/actionti.com\/en\/wp-json\/wp\/v2\/comments?post=309531"}],"version-history":[{"count":1,"href":"https:\/\/actionti.com\/en\/wp-json\/wp\/v2\/posts\/309531\/revisions"}],"predecessor-version":[{"id":309533,"href":"https:\/\/actionti.com\/en\/wp-json\/wp\/v2\/posts\/309531\/revisions\/309533"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/actionti.com\/en\/wp-json\/wp\/v2\/media\/309532"}],"wp:attachment":[{"href":"https:\/\/actionti.com\/en\/wp-json\/wp\/v2\/media?parent=309531"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/actionti.com\/en\/wp-json\/wp\/v2\/categories?post=309531"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}