chiminh.hungyen.gov.vn
CỔNG THÔNG TIN ĐIỆN TỬ XÃ CHÍ MINH - TỈNH HƯNG YÊN
NHIỆM VỤ, QUYỀN HẠN CỦA ỦY BAN NHÂN DÂN TỈNH
Lĩnh vực
- Pháp luật và Chính phủ / Chính phủ
Nguồn gốc
- Việt Nam
Xếp hạng toàn cầu
- #135.711
Xếp hạng tại Việt Nam
- #2.694
vi
CỔNG THÔNG TIN ĐIỆN TỬ XÃ CHÍ MINH - TỈNH HƯNG YÊN
NHIỆM VỤ, QUYỀN HẠN CỦA ỦY BAN NHÂN DÂN TỈNH
Điểm và hạng thể hiện kết quả đã ghi nhận tại thời điểm quét. Hãy xem từng hạng mục kiểm tra và bằng chứng để hiểu đầy đủ bối cảnh.
Báo cáo này tổng hợp các quan sát bảo mật đã ghi nhận cho chiminh.hungyen.gov.vn tại thời điểm quét. Hãy xem từng hạng mục và bằng chứng để hiểu đầy đủ bối cảnh.
CyStack chưa ghi nhận chiminh.hungyen.gov.vn hay hạ tầng liên quan trong bất kỳ danh sách cảnh báo lừa đảo, phishing hoặc mã độc nào tại thời điểm quét, sau khi đối chiếu 5 nguồn danh tiếng trực tuyến. Kết quả này phản ánh quan sát từ bên ngoài, không đảm bảo website an toàn tuyệt đối và không xác nhận tư cách pháp lý hay uy tín của tổ chức.
Nguồn dữ liệu
CyStack tổng hợp kết quả quét từ các hệ thống giám sát an ninh mạng nội bộ, bao gồm CyStack VulnScan và CyStack Threat Intelligence, cùng các nguồn dữ liệu công khai trên Internet. Quá trình đánh giá chỉ quan sát và phân tích thông tin sẵn có, không đăng nhập trái phép, thử mật khẩu, gửi mã khai thác hay làm thay đổi, gián đoạn hệ thống được đánh giá.
Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục trên toàn doanh nghiệp.
Có 3 tiêu chí không đạt hoặc cảnh báo có ảnh hưởng lớn nhất tới kết quả của chiminh.hungyen.gov.vn.
Vì sao cần quan tâm
Trình duyệt chỉ tin cậy website khi chứng thư có thể được xác minh tới một nhà cung cấp được công nhận. Chứng thư không đáng tin cậy gây cảnh báo và khiến người dùng không thể xác nhận chắc chắn danh tính website.
Nên làm gì
Cài chứng thư từ nhà cung cấp được các trình duyệt phổ biến tin cậy và cấu hình máy chủ gửi đầy đủ các chứng thư trung gian cần thiết.
Bằng chứng và phạm vi kiểm tra
Vì sao cần quan tâm
Một CVE có thể liên quan cũng nằm trong danh mục Known Exploited Vulnerabilities (KEV) của CISA, nghĩa là lỗ hổng đó đã bị dùng trong các cuộc tấn công thực tế. Kết quả cần được điều tra khẩn cấp nhưng vẫn phải xác nhận phần mềm đang cài có thực sự bị ảnh hưởng hay không.
Nên làm gì
Xác minh ngay sản phẩm đang cài và làm theo hướng dẫn của CISA cùng nhà cung cấp về biện pháp giảm thiểu, vá lỗi hoặc nâng cấp nếu sản phẩm bị ảnh hưởng.
Vì sao cần quan tâm
Thuộc tính Secure ngăn trình duyệt gửi cookie qua HTTP không mã hóa. Nếu thiếu thuộc tính này, dữ liệu phiên hoặc xác thực có thể bị lộ cho bên đang quan sát mạng.
Nên làm gì
Đặt Secure cho mọi cookie phiên, xác thực và cookie nhạy cảm khác của ứng dụng HTTPS.
Bằng chứng và phạm vi kiểm tra
Mỗi địa chỉ IP công khai được nhóm cùng dịch vụ đang mở, sản phẩm đã nhận diện và các CVE có khả năng liên quan đến phiên bản quan sát được.
Bằng chứng và phạm vi kiểm tra
Không hiển thị 16 trường bằng chứng bổ sung tại đây.
Tài liệu tham chiếu
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org/enCVE tiềm năng của sản phẩm này
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
NvdA security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
Nvdnginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
Nvdnginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
NvdSome HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
NvdSome HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.
NvdALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
NvdSome HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. This can consume excess memory.
Nvdnginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.
NvdNGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
NvdWhen multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key are used and/or the SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache are used in the default server and the default server is performing client certificate authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
NvdNginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org/enCVE tiềm năng của sản phẩm này
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
NvdA security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
Nvdnginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
Nvdnginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
NvdSome HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
NvdSome HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.
NvdALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
NvdSome HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. This can consume excess memory.
Nvdnginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.
NvdNGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
NvdWhen multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key are used and/or the SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache are used in the default server and the default server is performing client certificate authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
NvdBootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.comDataTables is a plug-in for the jQuery Javascript library adding advanced features like pagination, instant search, themes, and more to any HTML table.
datatables.netGoogle Analytics is a free web analytics service that tracks and reports website traffic.
google.com/analyticsHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org/rfc/rfc6797#section-6.1OWL Carousel is an enabled jQuery plugin that lets you create responsive carousel sliders.
owlcarousel2.github.io/OwlCarousel2YouTube is a video sharing service where users can create their own profile, upload videos, watch, like and comment on other videos.
www.youtube.comZurb Foundation is used to prototype in the browser. Allows rapid creation of websites or applications while leveraging mobile and responsive technology. The front end framework is the collection of HTML, CSS, and Javascript containing design patterns.
foundation.zurb.comjQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.comASP.NET is an open-source, server-side web-application framework designed for web development to produce dynamic web pages.
www.asp.netCác đánh giá hoàn tất gần đây, ưu tiên website cùng lĩnh vực, quốc gia hoặc mức an toàn để bạn dễ so sánh.