ufm.edu.vn có an toàn không? Điểm bảo mật 82,9/100 | CyStack
ufm.edu.vn
Trường Đại học Tài chính - Marketing
Trường Đại học Tài chính - Marketing đào tạo nguồn nhân lực theo tiêu chuẩn quốc gia và khu vực, chuyển giao những thành tựu khoa học về kinh doanh và quản lý; tham gia hoạch định chiến lược và chính sách cho ngành Tài chính, các doanh nghiệp và tổ chức xã hội.
Lĩnh vực
Khoa học và Giáo dục / Giáo dục
Nguồn gốc
Việt Nam
Xếp hạng toàn cầu
#64.330
Xếp hạng tại Việt Nam
#1.267
Cập nhật lúc
B82,9/100
Mức an toàn
Tốt
Độ tin cậy dữ liệu
Cao
Phạm vi đã kiểm tra
97,3%
Điểm càng cao, hệ thống càng ghi nhận được nhiều biện pháp bảo vệ quan sát từ bên ngoài. Trang này không nhằm chứng nhận website uy tín, hợp pháp hay hoàn toàn không có lỗ hổng.
Trang web “ufm.edu.vn” có an toàn không?
Tính đến 12:51 ngày 22/7/2026, ufm.edu.vn đạt 82,9/100 điểm an toàn (đạt hạng B – “Tốt”). Hệ thống quét tự động của CyStack ghi nhận 13 vấn đề cần xem xét sau khi kiểm tra 97,3% hạng mục. Chủ sở hữu website nên ưu tiên khắc phục “Các CVE tiềm năng đã được ghi nhận có khai thác”, sau đó rà soát các mục còn lại theo mức độ ảnh hưởng.
Có dấu hiệu lừa đảo, phishing hoặc mã độc nào liên quan đến ufm.edu.vn không?
CyStack chưa ghi nhận ufm.edu.vn hay hạ tầng liên quan trong bất kỳ danh sách cảnh báo lừa đảo, phishing hoặc mã độc nào tại thời điểm quét, sau khi đối chiếu 4 nguồn danh tiếng trực tuyến. Kết quả này phản ánh quan sát từ bên ngoài, không đảm bảo website an toàn tuyệt đối và không xác nhận tư cách pháp lý hay uy tín của tổ chức.
So sánh nhanh mức an toàn của từng nhóm hạng mục đã được đánh giá.
Bề mặt tấn công mạng95,5/100 · TốtĐã kiểm tra 100% nội dung của nhóm
An toàn web84,1/100 · KháĐã kiểm tra 100% nội dung của nhóm
Câu hỏi thường gặp
Điều gì đang ảnh hưởng đến độ an toàn của ufm.edu.vn?
Chứng thư SSL hợp lệ vẫn chưa đủ để khẳng định ufm.edu.vn là website an toàn, uy tín hay không có dấu hiệu lừa đảo. Để đánh giá toàn diện hơn, báo cáo còn kiểm tra phishing và mã độc, email lộ lọt, IP và cổng mở, tên miền phụ, công nghệ cùng các CVE có thể liên quan đến phiên bản ghi nhận được.
ufm.edu.vn có dùng HTTPS và chứng thư SSL còn hợp lệ không?
ufm.edu.vn đang dùng chứng thư SSL hợp lệ tại thời điểm đánh giá, có hiệu lực đến ngày 18 tháng 8, 2026. Trạng thái này có thể thay đổi khi chứng thư hết hạn hoặc máy chủ đổi cấu hình.
Email @ufm.edu.vn có xuất hiện trong dữ liệu lộ lọt hoặc nhật ký của phần mềm đánh cắp thông tin (infostealer) không?
Nguồn dữ liệu
Dữ liệu được tổng hợp từ các hệ thống giám sát an ninh mạng của CyStack
CyStack tổng hợp kết quả quét từ các hệ thống giám sát an ninh mạng nội bộ, bao gồm CyStack VulnScan và CyStack Threat Intelligence, cùng các nguồn dữ liệu công khai trên Internet. Quá trình đánh giá chỉ quan sát và phân tích thông tin sẵn có, không đăng nhập trái phép, thử mật khẩu, gửi mã khai thác hay làm thay đổi, gián đoạn hệ thống được đánh giá.
Hiện có 3 vấn đề nên ưu tiên xử lý trước vì ảnh hưởng lớn nhất đến mức độ an toàn của ufm.edu.vn.
Các CVE tiềm năng đã được ghi nhận có khai thácTìm thấy 3 ứng viên đã biết bị khai thác, nhưng dấu vân tay sản phẩm bên ngoài cần được xác minh.Nghiêm trọng
Kết quả kiểm tra
Tìm thấy 3 ứng viên đã biết bị khai thác, nhưng dấu vân tay sản phẩm bên ngoài cần được xác minh.
Vì sao cần quan tâm
Một CVE có thể liên quan cũng nằm trong danh mục Known Exploited Vulnerabilities (KEV) của CISA, nghĩa là lỗ hổng đó đã bị dùng trong các cuộc tấn công thực tế. Kết quả cần được điều tra khẩn cấp nhưng vẫn phải xác nhận phần mềm đang cài có thực sự bị ảnh hưởng hay không.
Nên làm gì
Xác minh ngay sản phẩm đang cài và làm theo hướng dẫn của CISA cùng nhà cung cấp về biện pháp giảm thiểu, vá lỗi hoặc nâng cấp nếu sản phẩm bị ảnh hưởng.
Các phiên bản TLS được hỗ trợCác phiên bản được chấp nhận: TLS 1.1, TLS 1.2, TLS 1.3.Cao
Kết quả kiểm tra
Các phiên bản được chấp nhận: TLS 1.1, TLS 1.2, TLS 1.3.
Vì sao cần quan tâm
TLS 1.0 và TLS 1.1 sử dụng thiết kế bảo mật lỗi thời và không còn được các tiêu chuẩn hiện đại chấp nhận. Việc tiếp tục bật chúng cho phép sử dụng phương thức kết nối yếu hơn.
Nên làm gì
Tắt TLS 1.0 và TLS 1.1, cấu hình TLS 1.2 an toàn và bật TLS 1.3 khi có thể.
Bảo vệ chống giả mạo email (DMARC)Không tìm thấy chính sách DMARC theo cơ chế duyệt cây tên miền.Cao
Kết quả kiểm tra
Không tìm thấy chính sách DMARC theo cơ chế duyệt cây tên miền.
Vì sao cần quan tâm
DMARC cho phép chủ tên miền hướng dẫn nơi nhận xử lý thư khi địa chỉ From hiển thị không được SPF hoặc DKIM xác minh. Nếu thiếu DMARC, kẻ tấn công có nhiều cơ hội giả mạo tên miền trong email lừa đảo.
Nên làm gì
Công bố bản ghi DMARC tại _dmarc, bắt đầu bằng việc thu thập báo cáo và xác nhận các nguồn gửi hợp lệ trước khi áp dụng chính sách chặn.
Mã hóa đường truyền
80,3/100 · Khá
Đã kiểm tra 100% nội dung của nhóm
Danh tiếng và chỉ báo đe dọa100/100 · TốtĐã kiểm tra 100% nội dung của nhóm
Rủi ro công nghệ và lỗ hổng57,1/100 · Cần xem xétĐã kiểm tra 100% nội dung của nhóm
Xác thực email63,9/100 · Cần xem xétĐã kiểm tra 100% nội dung của nhóm
Rò rỉ dữ liệu50/100 · Cần xem xétĐã kiểm tra 100% nội dung của nhóm
An toàn tên miền và DNS90/100 · TốtĐã kiểm tra 55,6% nội dung của nhóm
Vấn đề cần xem
Danh sách đầy đủ các vấn đề cần xem, bao gồm cả ba ưu tiên đã nêu ở phần tóm tắt.
Các CVE tiềm năng đã được ghi nhận có khai thácLỗ hổng phần mềmCần xem xét
Kết quả kiểm tra
Tìm thấy 3 ứng viên đã biết bị khai thác, nhưng dấu vân tay sản phẩm bên ngoài cần được xác minh.
Vì sao cần quan tâm
Một CVE có thể liên quan cũng nằm trong danh mục Known Exploited Vulnerabilities (KEV) của CISA, nghĩa là lỗ hổng đó đã bị dùng trong các cuộc tấn công thực tế. Kết quả cần được điều tra khẩn cấp nhưng vẫn phải xác nhận phần mềm đang cài có thực sự bị ảnh hưởng hay không.
Nên làm gì
Xác minh ngay sản phẩm đang cài và làm theo hướng dẫn của CISA cùng nhà cung cấp về biện pháp giảm thiểu, vá lỗi hoặc nâng cấp nếu sản phẩm bị ảnh hưởng.
Các phiên bản TLS được hỗ trợHTTPS và mã hóaKhông đạt
Kết quả kiểm tra
Các phiên bản được chấp nhận: TLS 1.1, TLS 1.2, TLS 1.3.
Vì sao cần quan tâm
TLS 1.0 và TLS 1.1 sử dụng thiết kế bảo mật lỗi thời và không còn được các tiêu chuẩn hiện đại chấp nhận. Việc tiếp tục bật chúng cho phép sử dụng phương thức kết nối yếu hơn.
Không tìm thấy chính sách DMARC theo cơ chế duyệt cây tên miền.
Vì sao cần quan tâm
DMARC cho phép chủ tên miền hướng dẫn nơi nhận xử lý thư khi địa chỉ From hiển thị không được SPF hoặc DKIM xác minh. Nếu thiếu DMARC, kẻ tấn công có nhiều cơ hội giả mạo tên miền trong email lừa đảo.
CSP đã tồn tại nhưng các chỉ thị rộng hoặc không an toàn làm suy yếu chính sách.
Vì sao cần quan tâm
Content Security Policy (CSP) giới hạn nguồn được phép cung cấp script, style, frame và nội dung khác cho trình duyệt. Chính sách chặt chẽ giúp giảm tác động nếu kẻ tấn công chèn được nội dung vào trang.
Nên làm gì
Hiệu lực và hạn dùng của chứng thưHTTPS và mã hóaCần xem xét
Kết quả kiểm tra
Chứng thư có hiệu lực từ 2025-08-12T00:00:00Z đến 2026-08-17T23:59:59Z.
Vì sao cần quan tâm
Chứng thư chỉ hoạt động trong khoảng thời gian hiệu lực. Chứng thư đã hết hạn, chưa có hiệu lực hoặc sắp hết hạn có thể gây cảnh báo trình duyệt và làm gián đoạn website hoặc API.
Nên làm gì
Các CVE có thể liên quan đến phiên bản phát hiện đượcLỗ hổng phần mềmCần xem xét
Kết quả kiểm tra
Tìm thấy 131 ứng viên CVE có khả năng áp dụng, trong đó 85 ứng viên mức high hoặc critical.
Vì sao cần quan tâm
Sản phẩm và phiên bản phát hiện được đã được đối chiếu với dữ liệu lỗ hổng của National Vulnerability Database (NVD). Kết quả khớp là đầu mối cần kiểm tra, chưa phải lỗ hổng đã xác nhận vì phần mềm cài đặt có thể đã chứa bản vá hoặc khác với phiên bản hiển thị ra Internet.
Thời hạn đăng ký tên miềnTên miền và DNSChưa xác định
Kết quả kiểm tra
Lần quét chưa thu thập đủ bằng chứng để đưa ra kết luận đáng tin cậy.
Vì sao cần quan tâm
Tên miền hết hạn sẽ ngừng đưa người dùng tới dịch vụ của tổ chức và cuối cùng có thể bị người khác đăng ký. Tên miền sắp hết hạn cũng khiến thời gian xử lý sự cố thanh toán hoặc tài khoản trở nên rất ngắn.
Nên làm gì
Gia hạn trước ngày hết hạn, bật tự động gia hạn và bảo vệ phương thức thanh toán cùng tài khoản nhà đăng ký.
Trạng thái đăng ký tên miềnTên miền và DNSChưa xác định
Kết quả kiểm tra
Lần quét chưa thu thập đủ bằng chứng để đưa ra kết luận đáng tin cậy.
Vì sao cần quan tâm
Các trạng thái hạn chế như khóa, chờ khôi phục hoặc chờ xóa có thể làm tên miền ngừng hoạt động. Nếu không xử lý kịp thời, tổ chức có thể mất quyền kiểm soát danh tính website và email.
Nên làm gì
Xử lý ngay các hạn chế đăng ký, bảo vệ tài khoản nhà đăng ký bằng MFA và cập nhật đầy đủ thông tin chủ sở hữu, liên hệ.
Tên miền phụ có thể chứa dịch vụ nhạy cảmHạ tầng công khaiCần xem xét
Kết quả kiểm tra
CyStack xác nhận ít nhất 100 tên miền phụ còn tồn tại trên DNS. Có 2 tên có thể liên quan đến dịch vụ nhạy cảm; dữ liệu hiện tại chưa đầy đủ nên thực tế có thể còn nhiều hơn.
Vì sao cần quan tâm
Tên chứa các từ như admin, development, staging, VPN, database hoặc monitoring có thể dẫn kẻ tấn công tới hệ thống quan trọng. Chỉ riêng tên gọi chưa chứng minh có lộ lọt nhưng cho biết bề mặt cần được rà soát.
Mức bảo vệ của SPFBảo vệ emailCần xem xét
Kết quả kiểm tra
Chính sách kết thúc SPF là ~all.
Vì sao cần quan tâm
Quy tắc cuối của SPF cho nơi nhận biết mức độ tin cậy khi từ chối nguồn gửi không có trong danh sách. Chính sách cho phép rộng khiến thư giả mạo dễ được xem là hợp lệ hơn so với hard fail (-all).
Nên làm gì
Xác nhận mọi nguồn gửi hợp lệ đã được khai báo, sau đó kết thúc bản ghi SPF bằng -all.
Phát hiện địa chỉ email của tên miền có dấu hiệu bị lộDữ liệu bị lộCần xem xét
Kết quả kiểm tra
119 bản ghi email lộ lọt có phần tên miền trùng chính xác với mục tiêu này, liên quan đến khoảng 48 thiết bị nhiễm mã độc. Đây là dữ liệu quan sát, không khẳng định tài khoản email vẫn hoạt động hoặc thiết bị thuộc tổ chức.
Vì sao cần quan tâm
Dữ liệu tình báo infostealer có thể chứa thông tin đăng nhập liên quan tới tên miền, nhưng không chứng minh tài khoản còn hiện hành, hợp lệ hoặc vẫn đang bị lộ.
Giới hạn tính năng trình duyệt (Permissions-Policy)Bảo vệ websiteKhông đạt
Kết quả kiểm tra
Kiểm tra này phát hiện một vấn đề bảo mật.
Vì sao cần quan tâm
Permissions-Policy kiểm soát việc trang và nội dung được nhúng có thể dùng camera, microphone, vị trí cùng các tính năng khác hay không. Cho phép tính năng không cần thiết sẽ tạo thêm đường truy cập ngoài nhu cầu.
Nên làm gì
Phiên bản phần mềm bị công khaiLỗ hổng phần mềmKhông đạt
Kết quả kiểm tra
Kiểm tra này phát hiện một vấn đề bảo mật.
Vì sao cần quan tâm
Phiên bản chính xác của web server hoặc framework giúp kẻ tấn công nhanh chóng tìm lỗ hổng đã biết có thể áp dụng. Ẩn phiên bản không thay thế việc vá lỗi, nhưng công khai không cần thiết sẽ cung cấp thông tin hữu ích cho việc nhắm mục tiêu.
Nên làm gì
Nhà cung cấp được phép cấp chứng thư (CAA)Tên miền và DNSCần xem xét
Kết quả kiểm tra
Tìm thấy 0 bản ghi CAA áp dụng.
Vì sao cần quan tâm
Bản ghi CAA quy định nhà cung cấp chứng thư nào được phép cấp chứng thư cho tên miền. Cấu hình này giúp giảm nguy cơ một nhà cung cấp ngoài dự kiến cấp chứng thư.
Nên làm gì
Công bố bản ghi CAA chỉ cho phép các nhà cung cấp chứng thư mà tổ chức thực sự sử dụng.
Bảo vệ phản hồi DNS (DNSSEC)Tên miền và DNSCần xem xét
Kết quả kiểm tra
Không tìm thấy ủy quyền DS của DNSSEC.
Vì sao cần quan tâm
DNSSEC thêm chữ ký số để hệ thống phân giải phát hiện phản hồi DNS giả mạo. Kiểm tra nhanh này xác nhận vùng cha có bản ghi DS nhưng không xác thực toàn bộ chuỗi chữ ký.
Nên làm gì
Ký vùng DNS, công bố bản ghi DS tương ứng qua nhà đăng ký và theo dõi chuỗi chữ ký sau mỗi lần thay đổi khóa.
Các tiêu chí đã đánh giá khác (37)
Chứng thư khớp với websiteHTTPS và mã hóa
Kết quả kiểm tra
Chứng thư khớp với mục tiêu được yêu cầu.
Vì sao cần quan tâm
Chứng thư phải liệt kê chính xác tên miền người dùng truy cập trong trường Subject Alternative Names (SAN). Nếu không khớp, trình duyệt sẽ cảnh báo vì chứng thư có thể thuộc về một dịch vụ khác.
Nên làm gì
Cấp và triển khai chứng thư có danh sách SAN bao gồm mọi tên miền công khai được địa chỉ website này phục vụ.
Dữ liệu hệ thống ghi nhận
Tên miền trong chứng thư số:
*.ufm.edu.vn, ufm.edu.vn
Tên miền được kiểm tra:
ufm.edu.vn
Chứng thư được trình duyệt tin cậyHTTPS và mã hóa
Kết quả kiểm tra
Chứng thư tạo được chuỗi tới gốc đáng tin cậy.
Vì sao cần quan tâm
Trình duyệt chỉ tin cậy website khi chứng thư có thể được xác minh tới một nhà cung cấp được công nhận. Chứng thư không đáng tin cậy gây cảnh báo và khiến người dùng không thể xác nhận chắc chắn danh tính website.
Nên làm gì
Cài chứng thư từ nhà cung cấp được các trình duyệt phổ biến tin cậy và cấu hình máy chủ gửi đầy đủ các chứng thư trung gian cần thiết.
Dữ liệu hệ thống ghi nhận
Đơn vị cấp chứng thư:
CN=Sectigo Public Server Authentication CA DV R36,O=Sectigo Limited,C=GB
Kết nối website an toàn (HTTPS)HTTPS và mã hóa
Kết quả kiểm tra
Bắt tay TLS thành công trên cổng 443.
Vì sao cần quan tâm
HTTPS mã hóa dữ liệu giữa người dùng và website, đồng thời giúp xác minh đúng dịch vụ cần truy cập. Nếu thiếu HTTPS, bên trung gian có thể đọc hoặc thay đổi lưu lượng và trình duyệt có thể hiện cảnh báo bảo mật.
Nên làm gì
Cung cấp toàn bộ website qua HTTPS bằng chứng thư được các trình duyệt phổ biến tin cậy.
Dữ liệu hệ thống ghi nhận
Bộ mã hóa:
TLS AES 256 GCM SHA384
Địa chỉ IP:
103.89.85.14
Phiên bản:
TLS 1.3
Bản ghi DNS công khaiTên miền và DNS
Kết quả kiểm tra
Mục tiêu phân giải tới 1 địa chỉ IP công khai.
Vì sao cần quan tâm
DNS công khai kết nối tên miền với các địa chỉ Internet của hệ thống. Bản ghi thiếu hoặc sai có thể làm dịch vụ không truy cập được hoặc đưa lưu lượng tới nhầm hệ thống.
Nên làm gì
Đảm bảo tên miền chỉ trỏ tới các địa chỉ IP công khai dự kiến và xóa bản ghi dùng địa chỉ riêng, dành riêng hoặc đã lỗi thời.
Dữ liệu hệ thống ghi nhận
Địa chỉ IP:
103.89.85.14
An toàn đường truyền của biểu mẫu mật khẩuBảo vệ websiteKhông áp dụng
Kết quả kiểm tra
Kiểm tra này không áp dụng cho mục tiêu.
Vì sao cần quan tâm
Nếu trang nhập mật khẩu hoặc địa chỉ nhận dữ liệu form dùng HTTP, bên quan sát đường truyền có thể đọc hoặc thay đổi mật khẩu được gửi.
Nên làm gì
Cung cấp mọi trang có trường mật khẩu qua HTTPS và gửi trực tiếp từng form mật khẩu tới một địa chỉ HTTPS.
Dữ liệu hệ thống ghi nhận
Biểu mẫu mật khẩu:
0
Mức độ công khai của dịch vụ quản trịHạ tầng công khai
Kết quả kiểm tra
Không phát hiện dịch vụ quản trị công khai trong tập cổng TCP đã quét.
Vì sao cần quan tâm
Dịch vụ quản trị từ xa như RDP, VNC, Docker, Kubernetes và bảng điều khiển là mục tiêu có giá trị cao. Khi mở công khai, bất kỳ ai trên Internet cũng có thể thử mật khẩu hoặc khai thác dịch vụ chưa được vá.
Nên làm gì
Loại bỏ truy cập trực tiếp từ Internet và yêu cầu VPN, cổng truy cập được bảo vệ chặt hoặc mạng nguồn tin cậy; đồng thời bật MFA khi dịch vụ hỗ trợ.
Dữ liệu hệ thống ghi nhận
Hoàn tất:
Có
Fingerprint Complete:
Có
Fingerprint Identified:
2
Fingerprint Targets:
2
Cơ sở dữ liệu hoặc cache mở ra InternetHạ tầng công khai
Kết quả kiểm tra
Không phát hiện dịch vụ kho dữ liệu công khai trong tập cổng TCP đã quét.
Vì sao cần quan tâm
Cơ sở dữ liệu và cache thường chứa thông tin nhạy cảm và chỉ được ứng dụng nội bộ sử dụng. Truy cập trực tiếp từ Internet khiến tấn công mật khẩu hoặc lỗi cấu hình dễ dẫn tới lộ dữ liệu hơn.
Nên làm gì
Chỉ lắng nghe trên giao diện mạng riêng, chỉ cho phép các hệ thống ứng dụng cần thiết kết nối và yêu cầu xác thực mạnh cùng mã hóa.
Dữ liệu hệ thống ghi nhận
Hoàn tất:
Có
Fingerprint Complete:
Có
Fingerprint Identified:
2
Fingerprint Targets:
2
Dịch vụ chia sẻ tệp mở ra InternetHạ tầng công khai
Kết quả kiểm tra
Không phát hiện dịch vụ chia sẻ tệp công khai trong tập cổng TCP đã quét.
Vì sao cần quan tâm
Các dịch vụ như SMB, NFS và rsync có thể cho phép đọc hoặc thay đổi tệp chia sẻ và từng có nhiều lỗ hổng nghiêm trọng. Chúng hiếm khi cần nhận kết nối trực tiếp từ Internet công khai.
Nên làm gì
Giới hạn dịch vụ chia sẻ tệp trong mạng riêng hoặc VPN được kiểm soát chặt và chỉ cho phép người dùng, hệ thống thực sự cần truy cập.
Dữ liệu hệ thống ghi nhận
Hoàn tất:
Có
Fingerprint Complete:
Có
Fingerprint Identified:
2
Fingerprint Targets:
2
Dịch vụ cũ không mã hóaHạ tầng công khai
Kết quả kiểm tra
Không phát hiện dịch vụ plaintext lỗi thời công khai trong tập cổng TCP đã quét.
Vì sao cần quan tâm
Các dịch vụ cũ như Telnet, FTP và giao thức email hoặc thư mục không mã hóa có thể gửi mật khẩu, dữ liệu ở dạng đọc được. Bên quan sát đường truyền có thể thu thập các thông tin này.
Nên làm gì
Tắt dịch vụ cũ hoặc thay bằng lựa chọn có mã hóa như SSH, SFTP, HTTPS hay phiên bản bảo mật của giao thức email.
Dữ liệu hệ thống ghi nhận
Hoàn tất:
Có
Fingerprint Complete:
Có
Fingerprint Identified:
2
Fingerprint Targets:
2
Quy tắc truy cập liên website (CORS)Bảo vệ website
Kết quả kiểm tra
Kiểm tra này không phát hiện vấn đề.
Vì sao cần quan tâm
CORS quyết định website nào được phép đọc phản hồi của dịch vụ trong trình duyệt người dùng. Quy tắc tin cậy nguồn tùy ý, đặc biệt khi kèm cookie đăng nhập, có thể làm lộ dữ liệu riêng tư cho website khác.
Nên làm gì
Chỉ cho phép các website tin cậy được xác định rõ, so sánh Origin với danh sách được duyệt chính xác và không bao giờ cho phép thông tin đăng nhập cùng nguồn ký tự đại diện (*).
Dữ liệu hệ thống ghi nhận
Chấp nhận nguồn tùy ý:
Không
Cho phép gửi thông tin xác thực:
Không
Cho phép mọi nguồn:
Có
Độ mạnh của khóa và chữ ký chứng thưHTTPS và mã hóa
Kết quả kiểm tra
Chứng thư dùng SHA256-RSA với khóa công khai 2048 bit.
Vì sao cần quan tâm
Khóa công khai và thuật toán chữ ký bảo vệ chứng thư khỏi bị giả mạo. Khóa quá ngắn hoặc chữ ký dùng thuật toán lỗi thời sẽ chống lại các kỹ thuật tấn công hiện đại kém hơn.
Nên làm gì
Sử dụng RSA tối thiểu 2048 bit hoặc khóa đường cong elliptic hiện đại, cùng thuật toán chữ ký SHA-256 trở lên.
Dữ liệu hệ thống ghi nhận
Thuật toán khóa công khai:
RSA
Độ dài khóa công khai:
2.048
Thuật toán chữ ký:
SHA256-RSA
Uy tín địa chỉ IP trên danh sách chặn DNSDanh tiếng IP
Kết quả kiểm tra
Không phát hiện đồng thuận abuse-list độc lập trong 4 nhà cung cấp có kết quả xác định.
Vì sao cần quan tâm
Các nhà cung cấp bảo mật và email duy trì danh sách chặn dựa trên DNS cho địa chỉ IP liên quan tới spam, mã độc hoặc hệ thống bị xâm nhập. Nhiều danh sách độc lập cùng gắn cờ là lý do rõ ràng để điều tra, dù IP dùng chung đôi khi có thể ảnh hưởng tới khách hàng không liên quan.
Nên làm gì
Xác minh từng danh sách với đúng địa chỉ IP, điều tra hoạt động email và máy chủ, xử lý nguyên nhân gốc rồi thực hiện quy trình yêu cầu gỡ của nhà cung cấp.
Dữ liệu hệ thống ghi nhận
Số danh sách không ghi nhận vấn đề:
4
Số cảnh báo được xác nhận:
Không
Số danh sách có kết quả rõ ràng:
4
Số danh sách không thể kiểm tra:
Cookie phiên được bảo vệ khỏi script (HttpOnly)Bảo vệ websiteKhông áp dụng
Kết quả kiểm tra
Kiểm tra này không áp dụng cho mục tiêu.
Vì sao cần quan tâm
HttpOnly ngăn script trong trình duyệt đọc trực tiếp cookie. Thuộc tính này không khắc phục lỗi chèn script nhưng khiến việc đánh cắp cookie phiên và xác thực khó hơn.
Nên làm gì
Đặt HttpOnly cho cookie phiên và xác thực, trừ khi ứng dụng có nhu cầu rõ ràng và được ghi nhận để đọc chúng bằng mã trong trình duyệt.
Cookie chỉ được gửi qua HTTPS (Secure)Bảo vệ websiteKhông áp dụng
Kết quả kiểm tra
Kiểm tra này không áp dụng cho mục tiêu.
Vì sao cần quan tâm
Thuộc tính Secure ngăn trình duyệt gửi cookie qua HTTP không mã hóa. Nếu thiếu thuộc tính này, dữ liệu phiên hoặc xác thực có thể bị lộ cho bên đang quan sát mạng.
Nên làm gì
Đặt Secure cho mọi cookie phiên, xác thực và cookie nhạy cảm khác của ứng dụng HTTPS.
Chính sách chặn của DMARCBảo vệ emailKhông áp dụng
Kết quả kiểm tra
Kiểm tra này không áp dụng cho mục tiêu.
Vì sao cần quan tâm
Chính sách quarantine hoặc reject yêu cầu nơi nhận đưa thư đáng ngờ vào spam hoặc từ chối thư. Chính sách chỉ theo dõi (p=none) ghi nhận vấn đề nhưng không yêu cầu chặn thư giả mạo.
Nên làm gì
Sau khi mọi nguồn gửi hợp lệ đều vượt qua DMARC, chuyển dần sang quarantine rồi reject và áp dụng cho 100% thư.
Nơi nhận có thể bỏ qua bản ghi DMARC chứa trường trùng, giá trị sai hoặc được công bố không đúng tên DNS. Bản ghi bị bỏ qua không tạo ra khả năng bảo vệ đáng tin cậy trước hành vi giả mạo tên miền.
Nên làm gì
Công bố một bản ghi DMARC hợp lệ tại _dmarc và sửa trường trùng, giá trị không được hỗ trợ cùng địa chỉ nhận báo cáo không hợp lệ.
Website khác có thể nhúng trang này vào một frame bị che hoặc gây hiểu nhầm để lừa người dùng bấm vào hành động ngoài ý muốn. Quy tắc frame cho trình duyệt biết website nào được phép nhúng trang.
Nên làm gì
Thiết lập frame-ancestors trong CSP chỉ cho các website tin cậy cần thiết và giữ X-Frame-Options cho trình duyệt cũ khi phù hợp.
Nội dung không an toàn trên trang HTTPSBảo vệ website
Kết quả kiểm tra
Kiểm tra này không phát hiện vấn đề.
Vì sao cần quan tâm
Trang HTTPS vẫn có thể tải script, frame, style hoặc form qua HTTP không mã hóa. Kẻ tấn công trên đường truyền có thể thay đổi nội dung đó và làm mất an toàn của toàn bộ trang.
Nên làm gì
Tải mọi script, frame, stylesheet và đích gửi form qua HTTPS; xóa hoặc thay thế tài nguyên không hỗ trợ HTTPS.
Dữ liệu hệ thống ghi nhận
Tài nguyên trang dùng HTTP không an toàn:
0
Xử lý đúng loại nội dung (nosniff)Bảo vệ website
Kết quả kiểm tra
Kiểm tra này không phát hiện vấn đề.
Vì sao cần quan tâm
Nếu thiếu nosniff, trình duyệt có thể tự đoán loại tệp và xử lý nội dung tưởng như vô hại thành mã có thể chạy. Khi đó, một Content-Type sai có thể trở thành vấn đề bảo mật.
Nên làm gì
Gửi X-Content-Type-Options: nosniff trên mọi phản hồi và trả về Content-Type chính xác.
Máy chủ phải cung cấp các chứng thư trung gian nối chứng thư website với nhà cung cấp đáng tin cậy. Nếu thiếu, một số trình duyệt, thiết bị di động hoặc API client có thể từ chối kết nối.
Nên làm gì
Cấu hình máy chủ gửi chứng thư website cùng toàn bộ chứng thư trung gian cần thiết, nhưng không gửi chứng thư gốc.
Dữ liệu hệ thống ghi nhận
Số chứng thư trong chuỗi:
4
Khả năng hỗ trợ HSTSHTTPS và mã hóa
Kết quả kiểm tra
Phản hồi HTTPS đã bật HSTS.
Vì sao cần quan tâm
HTTP Strict Transport Security (HSTS) yêu cầu trình duyệt tự động dùng HTTPS trong các lần truy cập sau. Cơ chế này giảm nguy cơ người dùng bị chuyển xuống kết nối không mã hóa.
Nên làm gì
Sau khi xác nhận mọi trang cần thiết hoạt động qua HTTPS, hãy gửi header Strict-Transport-Security trên tất cả phản hồi HTTPS.
Dữ liệu hệ thống ghi nhận
Áp dụng cho tên miền phụ:
Không
Thời gian hiệu lực (giây):
31.536.000
Yêu cầu trình duyệt tải sẵn:
Không
Đã cấu hình:
Có
Hợp lệ:
Tự động chuyển sang HTTPSHTTPS và mã hóa
Kết quả kiểm tra
Trang gốc HTTP chuyển hướng sang HTTPS trong phạm vi tên miền mục tiêu.
Vì sao cần quan tâm
Người dùng có thể nhập địa chỉ bắt đầu bằng HTTP hoặc mở một liên kết cũ. Chuyển hướng ngay sang HTTPS giúp phần còn lại của phiên truy cập không tiếp tục qua kết nối không mã hóa.
Nên làm gì
Chuyển hướng mọi URL HTTP trực tiếp tới URL HTTPS tương ứng, không đi qua một địa chỉ HTTP trung gian.
Dữ liệu hệ thống ghi nhận
Kết nối cuối:
https
Có thể truy cập website:
Có
Số lần chuyển hướng:
1
Danh sách thư mục công khaiLỗ hổng phần mềm
Kết quả kiểm tra
Trang gốc không khớp với mẫu liệt kê thư mục tự động phổ biến.
Vì sao cần quan tâm
Khi web server tự động liệt kê thư mục, người dùng có thể tìm thấy các tệp chưa từng được liên kết công khai, gồm bản sao lưu, log hoặc tệp phục vụ triển khai.
Nên làm gì
Tắt tự động liệt kê thư mục trừ khi duyệt tệp công khai là một tính năng có chủ đích và xóa tệp nhạy cảm khỏi các thư mục có thể truy cập qua web.
Dữ liệu hệ thống ghi nhận
Phát hiện dấu hiệu liệt kê thư mục:
Không
Chỉ kiểm tra trang chủ:
Có
Nguồn được phép gửi email (SPF)Bảo vệ email
Kết quả kiểm tra
Đã tìm thấy bản ghi SPF.
Vì sao cần quan tâm
SPF liệt kê các hệ thống được phép gửi email thay mặt tên miền. Nếu thiếu SPF, nơi nhận có ít căn cứ hơn để phân biệt thư hợp lệ với thư giả mạo.
Nên làm gì
Công bố một bản ghi TXT SPF bao gồm đầy đủ các dịch vụ gửi thư hợp lệ và không cho phép nguồn ngoài dự kiến.
Nhiều bản ghi SPF, nội dung sai hoặc quá nhiều truy vấn DNS có thể khiến SPF trả về lỗi cố định. Khi đó, nơi nhận có thể không xác minh được nguồn gửi hợp lệ.
Nên làm gì
Chỉ giữ một bản ghi SPF hợp lệ, sửa nội dung sai và tuân thủ giới hạn mười truy vấn dựa trên DNS của SPF.
Bản ghi MX chuyển email đến đúng máy chủ nhận thư. Bản ghi lỗi có thể làm gián đoạn việc nhận thư; Null MX cho biết rõ tên miền không nhận email.
Nên làm gì
Sửa máy chủ MX không truy cập được hoặc đã lỗi thời; nếu tên miền không dùng để nhận thư, hãy công bố Null MX.
Dữ liệu hệ thống ghi nhận
Không nhận email:
Không
Bảo vệ cookie khi truy cập liên trang (SameSite)Bảo vệ websiteKhông áp dụng
Kết quả kiểm tra
Kiểm tra này không áp dụng cho mục tiêu.
Vì sao cần quan tâm
SameSite giới hạn việc trình duyệt gửi cookie trong yêu cầu bắt đầu từ website khác. Cơ chế này giúp ngăn website khác âm thầm tạo yêu cầu đã xác thực thay mặt người dùng.
Nên làm gì
Ưu tiên SameSite=Lax hoặc Strict. Chỉ dùng SameSite=None cho luồng liên trang thực sự cần thiết và luôn kết hợp với Secure.
Dịch vụ công khai không cần thiếtHạ tầng công khai
Kết quả kiểm tra
Không phát hiện dịch vụ ngoài dự kiến công khai trong tập cổng TCP đã quét.
Vì sao cần quan tâm
Mọi dịch vụ đang mở đều có thể bị phát hiện, tấn công và cần được cấu hình, giám sát, vá lỗi. Dịch vụ không có mục đích công khai rõ ràng làm tăng rủi ro mà không tạo thêm giá trị.
Nên làm gì
Xác nhận đơn vị phụ trách và mục đích của từng cổng mở, sau đó dừng hoặc dùng firewall chặn mọi dịch vụ không chủ đích công khai.
Dữ liệu hệ thống ghi nhận
Hoàn tất:
Có
Fingerprint Complete:
Có
Fingerprint Identified:
2
Fingerprint Targets:
2
Quyền riêng tư của URL (Referrer-Policy)Bảo vệ website
Kết quả kiểm tra
Kiểm tra này không phát hiện vấn đề.
Vì sao cần quan tâm
Khi người dùng mở một liên kết, trình duyệt có thể gửi URL của trang trước đó tới website đích. Đường dẫn và tham số trong URL có thể làm lộ bối cảnh nhạy cảm cho website khác.
Nên làm gì
Sử dụng strict-origin-when-cross-origin hoặc Referrer-Policy chặt hơn, đồng thời không đặt thông tin bí mật trong URL.
Giá trị max-age quyết định thời gian trình duyệt ghi nhớ việc phải dùng HTTPS. Thời gian quá ngắn chỉ bảo vệ hạn chế; includeSubDomains bảo vệ mọi tên miền phụ nhưng có thể làm hỏng tên miền phụ chưa hỗ trợ HTTPS.
Nên làm gì
Sử dụng max-age dài và chỉ thêm includeSubDomains sau khi xác nhận mọi tên miền phụ đang hoạt động đều hỗ trợ HTTPS đúng cách.
Dữ liệu hệ thống ghi nhận
Áp dụng cho tên miền phụ:
Không
Thời gian hiệu lực (giây):
31.536.000
Yêu cầu trình duyệt tải sẵn:
Không
Đã cấu hình:
Có
Cấu hình nhận emailBảo vệ email
Kết quả kiểm tra
Tìm thấy 5 bản ghi MX; 0 đích không hợp lệ.
Vì sao cần quan tâm
Tên miền cần cho biết rõ có nhận email hay không. Nếu thiếu bản ghi MX hợp lệ hoặc Null MX, nơi gửi có thể thử chuyển thư tới máy chủ ngoài dự kiến và kết quả gửi nhận trở nên khó đoán.
Nên làm gì
Công bố bản ghi MX hợp lệ cho các máy chủ nhận thư dự kiến hoặc Null MX nếu tên miền hoàn toàn không nhận email.
Dữ liệu hệ thống ghi nhận
Không nhận email:
Không
Khả năng dự phòng của dịch vụ DNSTên miền và DNS
Kết quả kiểm tra
Tìm thấy 2 máy chủ DNS có thẩm quyền.
Vì sao cần quan tâm
Máy chủ DNS có thẩm quyền cho người dùng biết website và email được đặt ở đâu. Chỉ phụ thuộc vào một máy chủ sẽ tạo ra một điểm lỗi duy nhất.
Nên làm gì
Sử dụng ít nhất hai máy chủ DNS có thẩm quyền, ưu tiên hạ tầng độc lập và có khả năng dự phòng.
Dữ liệu hệ thống ghi nhận
Máy chủ DNS:
hcmc3.saigonnet.vn, hcmc4.saigonnet.vn
Báo cáo giám sát DMARCBảo vệ emailKhông áp dụng
Kết quả kiểm tra
Kiểm tra này không áp dụng cho mục tiêu.
Vì sao cần quan tâm
Báo cáo tổng hợp DMARC cho biết hệ thống nào gửi email bằng tên miền và thư nào không vượt qua xác minh. Báo cáo giúp phát hiện cả hành vi giả mạo lẫn dịch vụ hợp lệ cần sửa cấu hình.
Nên làm gì
Thêm địa chỉ nhận báo cáo tổng hợp (rua) được bảo vệ và theo dõi hoặc sử dụng một dịch vụ báo cáo DMARC đáng tin cậy.
Phạm vi kiểm tra danh sách chặnDanh tiếng IPThông tin
Kết quả kiểm tra
4 nhà cung cấp có kết quả xác định và 2 nhà cung cấp chưa thể kết luận.
Vì sao cần quan tâm
Mục này cho biết có bao nhiêu dịch vụ danh sách chặn độc lập trả về kết quả rõ ràng. Nguồn không khả dụng chưa được kiểm tra thành công và không thể được xem là kết quả sạch.
Dữ liệu hệ thống ghi nhận
Số danh sách không ghi nhận vấn đề:
4
Số cảnh báo được xác nhận:
Không
Số danh sách có kết quả rõ ràng:
4
Số danh sách không thể kiểm tra:
2
Công nghệ quan sát được từ InternetLỗ hổng phần mềmThông tin
Kết quả kiểm tra
Các dấu hiệu công khai từ website và dịch vụ đang mở cho thấy 9 công nghệ.
Vì sao cần quan tâm
Header phản hồi, nội dung trang và các dấu hiệu công khai khác cho biết công nghệ mà dịch vụ có thể đang sử dụng. Quan sát này giúp giải thích bề mặt tấn công nhưng có thể thiếu hoặc sai và không tự chứng minh một lỗ hổng.
Dữ liệu hệ thống ghi nhận
Số công nghệ phát hiện:
9
Cách phát hiện:
Phân tích website và dịch vụ đang mở
Root Response Count:
9
Service Inventory Complete:
Có
WAF, CDN hoặc dịch vụ biên quan sát đượcLỗ hổng phần mềmThông tin
Kết quả kiểm tra
Không có sản phẩm WAF, CDN hoặc edge nào khớp với tín hiệu thụ động trên phản hồi trang gốc; kết quả này không chứng minh hệ thống không có lớp bảo vệ.
Vì sao cần quan tâm
Chi tiết phản hồi công khai cho thấy có thể đang sử dụng Web Application Firewall (WAF), CDN hoặc dịch vụ biên khác. Lần quét nhanh nhận diện nhà cung cấp nhưng không kiểm tra khả năng chặn tấn công đã được cấu hình hoặc hoạt động đúng hay chưa.
Dữ liệu hệ thống ghi nhận
Phát hiện lớp bảo vệ:
Không
Cách phát hiện:
Dấu hiệu từ phản hồi web
Phạm vi tra cứu lỗ hổng phần mềmLỗ hổng phần mềmThông tin
Kết quả kiểm tra
Quan sát 6 sản phẩm có phiên bản; 4 sản phẩm có CPE chính xác và 4 truy vấn hoàn tất.
Vì sao cần quan tâm
Mục này cho biết có bao nhiêu sản phẩm được phát hiện có thông tin phiên bản đáng tin cậy và định danh CPE chính xác để đối chiếu với dữ liệu áp dụng CVE. Sản phẩm chưa thể kiểm tra không được xem là không có lỗ hổng đã biết.
Nhận diện lớp bảo vệ website và kiểm tra IP có bị các danh sách cảnh báo gắn cờ hay không.
WAF và bảo vệ biên
Chưa nhận diện đượcKhông nhận diện được WAF không có nghĩa website chắc chắn không sử dụng WAF.
Danh sách cảnh báo IP
Không xác nhận bị liệt kê
IP xác nhận bị liệt kê
—
Nguồn không gắn cờ
4
DNS, email và đăng ký tên miền
Kiểm tra tên miền, email và các cấu hình giúp ngăn giả mạo thương hiệu.
Bảo vệ DNSSEC
Không
Máy chủ tên miền
hcmc3.saigonnet.vn, hcmc4.saigonnet.vn
Chính sách SPF
v=spf1 include:_spf.google.com ~all
Chính sách DMARC
Địa chỉ email của tên miền có dấu hiệu bị lộChỉ đối chiếu các địa chỉ email có phần sau dấu @ trùng chính xác với tên miền đang quét trong dữ liệu infostealer. Bản ghi không được tính chỉ vì người dùng từng truy cập hoặc đăng nhập website này.119 Bản ghi email lộ lọt khớp tên miền
119Bản ghi email lộ lọt khớp tên miền
48Thiết bị nhiễm mã độc liên quan (ước tính)
Các bản ghi email khớp này từng được quan sát nhưng có thể đã được xử lý hoặc không còn hiệu lực. Số thiết bị là ước tính thiết bị nhiễm mã độc có liên quan đến các bản ghi email đó, không phải số thiết bị của tổ chức.
Bằng chứng lộ lọtGhi nhận gần nhất:
Địa chỉ emailThiết bị nhiễm mã độc liên quanDấu vết mã độcThời gian ghi nhận
Địa chỉ email1*********@ufm.edu.vnThiết bị nhiễm mã độc liên quanD************** (Windows 10 x64)SingaporeMã đối chiếu IOC: IOC-EE3DECE2EA
Chỉ hiển thị tối đa 10 bản ghi gần nhất đã được che để bảo vệ thông tin nhạy cảm.
Tên miền phụ đã tìm thấy (100+)Danh sách tên miền phụ do CyStack khám phá; những tên có vẻ nhạy cảm được đưa lên trước. Khả năng truy cập được xác minh trong lần đánh giá này; từng tên miền phụ chưa được quét bảo mật riêng lẻ.Một phần
demo.ufm.edu.vnCó dấu hiệu nhạy cảmPhát triển / kiểm thử
dev.ufm.edu.vnCó dấu hiệu nhạy cảmPhát triển / kiểm thử
Bối cảnh web công khaiTiêu đề, mô tả, lĩnh vực hoạt động và mức độ phổ biến của website.
Tiêu đề trang
Trường Đại học Tài chính - Marketing
Nhóm website
Khoa học và Giáo dục / Giáo dục
Mô tả
Trường Đại học Tài chính - Marketing đào tạo nguồn nhân lực theo tiêu chuẩn quốc gia và khu vực, chuyển giao những thành tựu khoa học về kinh doanh và quản lý; tham gia hoạch định chiến lược và chính sách cho ngành Tài chính, các doanh nghiệp và tổ chức xã hội.
Xếp hạng toàn cầu
#64.330
Xếp hạng tại Việt Nam
#1.267
Xếp hạng trong lĩnh vực
#78
Đây là kiểm tra nhanh từ bên ngoài tại một thời điểm. Kết quả giúp phát hiện sớm rủi ro dễ quan sát nhưng không thay thế kiểm thử xâm nhập hoặc đánh giá có xác thực.
Hiện ghi nhận 119 bản ghi email lộ lọt khớp tên miền ufm.edu.vn. Các bản ghi này có thể đã cũ hoặc đã được xử lý. Chủ sở hữu website nên xác minh trước khi đổi mật khẩu hoặc khóa các tài khoản liên quan.
ufm.edu.vn đang công khai những IP, dịch vụ và cổng nào?
Quan sát được 1 IP công khai và 2 cổng đang mở của ufm.edu.vn; hạ tầng có dấu hiệu được vận hành bởi Cong ty CP Cong Nghe Tien Phat-Chi Nhanh Ha Noi. Cổng mở không mặc nhiên là lỗ hổng, nhưng mỗi dịch vụ công khai đều cần được cập nhật và giới hạn truy cập phù hợp.
Đã phát hiện được bao nhiêu tên miền phụ của ufm.edu.vn?
Ghi nhận 100+ tên miền phụ công khai của ufm.edu.vn. Danh sách này giúp nhận biết thêm các cổng vào như API, hệ thống quản trị hay môi trường thử nghiệm, nhưng không có nghĩa tên miền phụ nào cũng có rủi ro.
Chỉ khai báo các nguồn ứng dụng thực sự cần, kiểm thử chính sách trước khi kích hoạt và hạn chế quy tắc ký tự đại diện (*) quá rộng, unsafe-inline cùng unsafe-eval.
Sử dụng gia hạn tự động, theo dõi lỗi gia hạn và cảnh báo cho đội phụ trách từ sớm trước ngày hết hạn.
Dữ liệu hệ thống ghi nhận
Số ngày còn lại:
26,8
Hết hiệu lực lúc:
Có hiệu lực từ:
Nên làm gì
Xác nhận chính xác gói phần mềm đang cài và đọc cảnh báo của nhà cung cấp. Nếu bản cài đặt thực sự bị ảnh hưởng, hãy áp dụng bản vá hoặc nâng cấp lên phiên bản đã sửa lỗi.
Kiểm tra bằng chứng đã che và thời gian quan sát, xác minh tài khoản cùng thiết bị bị ảnh hưởng, sau đó đặt lại thông tin đăng nhập và phiên còn hiệu lực, bắt buộc MFA và loại bỏ malware khi được xác nhận.
Dữ liệu hệ thống ghi nhận
Thiết bị bị ảnh hưởng đã ghi nhận:
48
Thiết bị nhiễm mã độc (ước tính):
48
Evidence Mask Policy:
Length Preserving V2
Mẫu bằng chứng đang hiển thị:
10
Giới hạn mẫu bằng chứng:
10
Có thể xem mẫu bằng chứng:
Có
Còn mẫu bằng chứng chưa hiển thị:
Có
Bản ghi email bị lộ khớp tên miền:
119
Cách đối chiếu bản ghi email bị lộ:
Chỉ tính email có tên miền trùng khớp với website
Ghi nhận gần nhất:
Chỉ cho phép từng tính năng nhạy cảm trên các trang và nguồn tin cậy thực sự cần dùng; tắt các tính năng còn lại.
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.
Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected. Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.
Hệ thống tìm thấy 83 kết quả tiềm năng cho sản phẩm này, nhưng báo cáo chỉ lưu một phần chi tiết đại diện.
OOpenSSL1.1.1cWeb Server Extensions1.1.1c44 CVE có thể liên quanCVSS 9,8
Định danh CPEcpe:2.3:a:openssl:openssl:1.1.1c:*:*:*:*:*:*:*
Độ tin cậyTrung bình
OpenSSL is a software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end.
JjQuery2.2.4JavaScript Libraries2.2.44 CVE có thể liên quanKEVCVSS 6,1
Định danh CPEcpe:2.3:a:jquery:jquery:2.2.4:*:*:*:*:*:*:*
Độ tin cậyTrung bình
jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
OOpenSSL1.1.1cWeb Server Extensions1.1.1c44 CVE có thể liên quanCVSS 9,8
Định danh CPEcpe:2.3:a:openssl:openssl:1.1.1c:*:*:*:*:*:*:*
Độ tin cậyTrung bình
OpenSSL is a software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end.
BootstrapCDN is a powerful and reliable Content Delivery Network (CDN) that delivers static resources, including CSS, JavaScript, and font files, for the widely-used Bootstrap framework. By leveraging multiple server locations worldwide, BootstrapCDN accelerates website loading times, ensuring a smooth and visually appealing user experience. Additionally, it ensures website compatibility with various devices and browsers. The service reduces bandwidth usage and server load, improving web performance for developers and end-users alike.
Định danh CPEcpe:2.3:a:getbootstrap:bootstrap:4.3.1:*:*:*:*:*:*:*
Độ tin cậyTrung bình
Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
Địa chỉ email1*********@ufm.edu.vnThiết bị nhiễm mã độc liên quanChưa có thông tin thiết bị nào đủ an toàn để hiển thị cho bản ghi này.ChileMã đối chiếu IOC: IOC-369FEC448DDấu vết mã độcCSBradmaxCookiesOnlyStealerThời gian ghi nhận
Địa chỉ email1************@ufm.edu.vnThiết bị nhiễm mã độc liên quanD************** (Windows 10 Pro)Việt NamMã đối chiếu IOC: IOC-0858D7DE27Dấu vết mã độcVidarỨng dụng được ghi nhận: Google Chrome (Default)Thời gian ghi nhận
Địa chỉ email1************@ufm.edu.vnThiết bị nhiễm mã độc liên quan(Windows 10 Pro)Việt NamMã đối chiếu IOC: IOC-7995246596Dấu vết mã độcVidarỨng dụng được ghi nhận: Google Chrome (Default)Thời gian ghi nhận
Địa chỉ email1*********@ufm.edu.vnThiết bị nhiễm mã độc liên quanZ******************Mã đối chiếu IOC: IOC-3A970AE4EADấu vết mã độcMacSyncỨng dụng được ghi nhận: Edge_DefaultThời gian ghi nhận
Địa chỉ email1************@ufm.edu.vnThiết bị nhiễm mã độc liên quan(Windows 10)Việt NamMã đối chiếu IOC: IOC-E43692DA88Dấu vết mã độcMillenium RATỨng dụng được ghi nhận: Chrome, Profile: 2Ứng dụng có quyền quản trịThời gian ghi nhận
Địa chỉ email1************@ufm.edu.vnThiết bị nhiễm mã độc liên quan(Windows 10)Việt NamMã đối chiếu IOC: IOC-E43692DA88Dấu vết mã độcMillenium RATỨng dụng được ghi nhận: Chrome, Profile: 2Ứng dụng có quyền quản trịThời gian ghi nhận
Địa chỉ email1*********@ufm.edu.vnThiết bị nhiễm mã độc liên quan(Windows 10)Việt NamMã đối chiếu IOC: IOC-E43692DA88Dấu vết mã độcMillenium RATỨng dụng được ghi nhận: Chrome, Profile: 2Ứng dụng có quyền quản trịThời gian ghi nhận
Địa chỉ emailt*******@ufm.edu.vnThiết bị nhiễm mã độc liên quanM** (Windows 11 24H2 build 26100 (64 Bit))Việt NamMã đối chiếu IOC: IOC-E6C8AA4875Dấu vết mã độcRedlineLike StealerỨng dụng được ghi nhận: Browser/Logins/Chrome_Default[f4a00ef5].txtThời gian ghi nhận
Địa chỉ email1************@ufm.edu.vnThiết bị nhiễm mã độc liên quanM******************* (macOS 13.3.1 (22E261))Mã đối chiếu IOC: IOC-EEEA45C463Dấu vết mã độcAMOS StealerThời gian ghi nhận
4t.ufm.edu.vn
50years.ufm.edu.vn
app.ufm.edu.vn
banllcb.ufm.edu.vn
bantin45nam.ufm.edu.vn
cd.ufm.edu.vn
cflit.ufm.edu.vn
chatluongcao.ufm.edu.vn
cic.ufm.edu.vn
cuusinhvien.ufm.edu.vn
Hiện thêm 88 mục
dacc.ufm.edu.vn
dacenter.ufm.edu.vn
daotaosdh.ufm.edu.vn
daotaotuxa.ufm.edu.vn
datacenter.ufm.edu.vn
dbchatluong.ufm.edu.vn
doanhnghiephoptacdaotao.ufm.edu.vn
doanthanhnien.ufm.edu.vn
dongnai.ufm.edu.vn
eng.ufm.edu.vn
eoffice.ufm.edu.vn
gdqp.ufm.edu.vn
giangvien.ufm.edu.vn
hccb.ufm.edu.vn
hieutruongtaloi.ufm.edu.vn
hieutruongtraloi.ufm.edu.vn
hoatdong.ufm.edu.vn
iae.ufm.edu.vn
ice.ufm.edu.vn
idt.ufm.edu.vn
isfm.ufm.edu.vn
isfmf.ufm.edu.vn
jfm.ufm.edu.vn
khoacntt.ufm.edu.vn
khoaketoan.ufm.edu.vn
khoakhdl.ufm.edu.vn
khoakinhteluat.ufm.edu.vn
khoaluat.ufm.edu.vn
khoalyluanchinhtri.ufm.edu.vn
khoamarketing.ufm.edu.vn
khoangoaingu.ufm.edu.vn
khoaqtkd.ufm.edu.vn
khoasaudaihoc.ufm.edu.vn
khoataichinhnganhang.ufm.edu.vn
khoataichuc.ufm.edu.vn
khoathamdinhgia.ufm.edu.vn
khoathuehaiquan.ufm.edu.vn
khoathuongmai.ufm.edu.vn
khoathuongmaidulich.ufm.edu.vn
ktcnh.ufm.edu.vn
kytucxa.ufm.edu.vn
linux.ufm.edu.vn
lms.daotaotuxa.ufm.edu.vn
login.ufm.edu.vnHệ thống đăng nhập
mail.ufm.edu.vnHệ thống email
media.ufm.edu.vnNội dung đa phương tiện
ngayhoituyendung.ufm.edu.vn
nhaphoc.ufm.edu.vn
nnth.ufm.edu.vn
pdt.ufm.edu.vn
phongkhtc.ufm.edu.vn
phongqldt.ufm.edu.vn
phongqlkh.ufm.edu.vn
phongqlktx.ufm.edu.vn
phongqlts.ufm.edu.vn
phongqttb.ufm.edu.vn
phongquanlykhoahoc.ufm.edu.vn
phongtchc.ufm.edu.vn
phongthanhtra.ufm.edu.vn
phongttpc.ufm.edu.vn
pvpdu.ufm.edu.vn
qlkhdmst.ufm.edu.vn
quangngai.ufm.edu.vn
quanlyctkh.ufm.edu.vn
regist.ufm.edu.vn
shcd.ufm.edu.vn
shop.ufm.edu.vnThương mại
sinhvien.ufm.edu.vn
sip.ufm.edu.vnDịch vụ thời gian thực
slide.ufm.edu.vn
thin.ufm.edu.vn
thuvien.ufm.edu.vn
tramyte.ufm.edu.vn
trungtamnctt.ufm.edu.vn
truongquay.ufm.edu.vn
tsqhdn.ufm.edu.vn
tuyensinhtructuyen.ufm.edu.vn
u003ekhoathuongmai.ufm.edu.vn
ubuntu.ufm.edu.vn
uis.ufm.edu.vn
vareb.ufm.edu.vn
vieclam.ufm.edu.vn
viencntcnh.ufm.edu.vn
vpdu.ufm.edu.vn
vsat.ufm.edu.vn
workspace.ufm.edu.vn
xemdiemthpt.ufm.edu.vn
xettuyen.ufm.edu.vn
URL cuối
https://ufm.edu.vn/
Xếp hạng và lĩnh vực website theo dữ liệu của Similarweb
CVSS 9
Sản phẩm đối chiếu: HTTPD 2.4.41 Độ tin cậy: Cao
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.
Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack.
Configurations are affected when mod_proxy is enabled along with some form of RewriteRule
or ProxyPassMatch in which a non-specific pattern matches
some portion of the user-supplied request-target (URL) data and is then
re-inserted into the proxied request-target using variable
substitution. For example, something like:
RewriteEngine on
RewriteRule "^/here/(.*)" "http://example.com:8080/elsewhere?$1"; [P]
ProxyPassReverse /here/ http://example.com:8080/
Request splitting/smuggling could result in bypass of access controls in the proxy server, proxying unintended URLs to existing origin servers, and cache poisoning. Users are recommended to update to at least version 2.4.56 of Apache HTTP Server.
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in
directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.
Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may hypothetically be affected.
In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption.
Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of trusted client certificates (for example with a different SSLCACertificateFile/Path setting). In such a case, a client trusted to access one virtual host may be able to access another virtual host, if SSLStrictSNIVHostCheck is not enabled in either virtual host.
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.54 and prior versions.
An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
Users are recommended to upgrade to version 2.4.67, which fixes this issue.
Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives.
This issue affects Apache HTTP Server before 2.4.66.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the decrypted plaintext. The application can then allocate a sufficiently sized buffer and call EVP_PKEY_decrypt() again, but this time passing a non-NULL value for the "out" parameter. A bug in the implementation of the SM2 decryption code means that the calculation of the buffer size required to hold the plaintext returned by the first call to EVP_PKEY_decrypt() can be smaller than the actual size required by the second call. This can lead to a buffer overflow when EVP_PKEY_decrypt() is called by the application a second time with a buffer that is too small. A malicious attacker who is able present SM2 content for decryption to an application could cause attacker chosen data to overflow the buffer by up to a maximum of 62 bytes altering the contents of other data held after the buffer, possibly changing application behaviour or causing the application to crash. The location of the buffer is application dependent but is typically heap allocated. Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k).
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could
trigger a use-after-free during PKCS#7 signature verification.
Impact summary: A use-after-free may result in process crashes, heap
corruption, or potentially remote code execution.
When processing a PKCS#7 or S/MIME signed message, if the SignedData
digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may
incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent
use of the BIO by the calling application results in a use-after-free
condition.
In the common case this occurs when the application later calls
BIO_free() on the BIO originally passed to PKCS7_verify(). Depending
on allocator behavior and application-specific BIO usage patterns, this
may result in a crash or other memory corruption. In some application
contexts this may potentially be exploitable for remote code execution.
Applications that process PKCS#7 or S/MIME signed messages using OpenSSL
PKCS#7 APIs may be affected. Applications using the CMS APIs for this
processing are not affected.
The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this
issue, as the affected code is outside the OpenSSL FIPS module boundary.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: An uncommon configuration of clients performing DANE TLSA-based
server authentication, when paired with uncommon server DANE TLSA records, may
result in a use-after-free and/or double-free on the client side.
Impact summary: A use after free can have a range of potential consequences
such as the corruption of valid data, crashes or execution of arbitrary code.
However, the issue only affects clients that make use of TLSA records with both
the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate
usage.
By far the most common deployment of DANE is in SMTP MTAs for which RFC7672
recommends that clients treat as 'unusable' any TLSA records that have the PKIX
certificate usages. These SMTP (or other similar) clients are not vulnerable
to this issue. Conversely, any clients that support only the PKIX usages, and
ignore the DANE-TA(2) usage are also not vulnerable.
The client would also need to be communicating with a server that publishes a
TLSA RRset with both types of TLSA records.
No FIPS modules are affected by this issue, the problem code is outside the
FIPS module boundary.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: A signed integer overflow when sizing the destination
buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap
buffer overflow.
Impact summary: A heap buffer overflow may lead to a crash or possibly
attacker controlled code execution or other undefined behaviour.
In ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination
size for Unicode output is computed in a signed int: by left shift
of the input character count for BMPSTRING (UTF-16) and
UNIVERSALSTRING (UTF-32), and by summing per-character byte counts
for UTF8STRING. The calculation overflows when the input reaches
around 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30
characters) the size wraps to zero, OPENSSL_malloc(1) is called, and
the subsequent character copy writes several gigabytes past the
one-byte allocation.
X.509 certificate processing routes through ASN1_STRING_set_by_NID(),
whose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID
size limits cap the input length; no network protocol or
certificate-handling path in OpenSSL exercises the overflow.
Triggering the bug requires an application that calls
ASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers
a custom string type via ASN1_STRING_TABLE_add(), with
attacker-controlled input on the order of half a gigabyte or more.
For these reasons this issue was assigned Low severity.
The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by
this issue, as the affected code is outside the OpenSSL FIPS module
boundary.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: The POLY1305 MAC (message authentication code) implementation
contains a bug that might corrupt the internal state of applications on the
Windows 64 platform when running on newer X86_64 processors supporting the
AVX512-IFMA instructions.
Impact summary: If in an application that uses the OpenSSL library an attacker
can influence whether the POLY1305 MAC algorithm is used, the application
state might be corrupted with various application dependent consequences.
The POLY1305 MAC (message authentication code) implementation in OpenSSL does
not save the contents of non-volatile XMM registers on Windows 64 platform
when calculating the MAC of data larger than 64 bytes. Before returning to
the caller all the XMM registers are set to zero rather than restoring their
previous content. The vulnerable code is used only on newer x86_64 processors
supporting the AVX512-IFMA instructions.
The consequences of this kind of internal application state corruption can
be various - from no consequences, if the calling application does not
depend on the contents of non-volatile XMM registers at all, to the worst
consequences, where the attacker could get complete control of the application
process. However given the contents of the registers are just zeroized so
the attacker cannot put arbitrary values inside, the most likely consequence,
if any, would be an incorrect result of some application dependent
calculations or a crash leading to a denial of service.
The POLY1305 MAC algorithm is most frequently used as part of the
CHACHA20-POLY1305 AEAD (authenticated encryption with associated data)
algorithm. The most common usage of this AEAD cipher is with TLS protocol
versions 1.2 and 1.3 and a malicious client can influence whether this AEAD
cipher is used by the server. This implies that server applications using
OpenSSL can be potentially impacted. However we are currently not aware of
any concrete application that would be affected by this issue therefore we
consider this a Low severity security issue.
As a workaround the AVX512-IFMA instructions support can be disabled at
runtime by setting the environment variable OPENSSL_ia32cap:
OPENSSL_ia32cap=:~0x200000
The FIPS provider is not affected by this issue.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022. Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc).
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and
decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data.
If the function succeeds then the "name_out", "header" and "data" arguments are
populated with pointers to buffers containing the relevant decoded data. The
caller is responsible for freeing those buffers. It is possible to construct a
PEM file that results in 0 bytes of payload data. In this case PEM_read_bio_ex()
will return a failure code but will populate the header argument with a pointer
to a buffer that has already been freed. If the caller also frees this buffer
then a double free will occur. This will most likely lead to a crash. This
could be exploited by an attacker who has the ability to supply malicious PEM
files for parsing to achieve a denial of service attack.
The functions PEM_read_bio() and PEM_read() are simple wrappers around
PEM_read_bio_ex() and therefore these functions are also directly affected.
These functions are also called indirectly by a number of other OpenSSL
functions including PEM_X509_INFO_read_bio_ex() and
SSL_CTX_use_serverinfo_file() which are also vulnerable. Some OpenSSL internal
uses of these functions are not vulnerable because the caller does not free the
header argument if PEM_read_bio_ex() returns a failure code. These locations
include the PEM_read_bio_TYPE() functions as well as the decoders introduced in
OpenSSL 3.0.
The OpenSSL asn1parse command line application is also impacted by this issue.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
The public API function BIO_new_NDEF is a helper function used for streaming
ASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the
SMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by
end user applications.
The function receives a BIO from the caller, prepends a new BIO_f_asn1 filter
BIO onto the front of it to form a BIO chain, and then returns the new head of
the BIO chain to the caller. Under certain conditions, for example if a CMS
recipient public key is invalid, the new filter BIO is freed and the function
returns a NULL result indicating a failure. However, in this case, the BIO chain
is not properly cleaned up and the BIO passed by the caller still retains
internal pointers to the previously freed filter BIO. If the caller then goes on
to call BIO_pop() on the BIO then a use-after-free will occur. This will most
likely result in a crash.
This scenario occurs directly in the internal function B64_write_ASN1() which
may cause BIO_new_NDEF() to be called and will subsequently call BIO_pop() on
the BIO. This internal function is in turn called by the public API functions
PEM_write_bio_ASN1_stream, PEM_write_bio_CMS_stream, PEM_write_bio_PKCS7_stream,
SMIME_write_ASN1, SMIME_write_CMS and SMIME_write_PKCS7.
Other public API functions that may be impacted by this include
i2d_ASN1_bio_stream, BIO_new_CMS, BIO_new_PKCS7, i2d_CMS_bio_stream and
i2d_PKCS7_bio_stream.
The OpenSSL cms and smime command line applications are similarly affected.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
A security vulnerability has been identified in all supported versions
of OpenSSL related to the verification of X.509 certificate chains
that include policy constraints. Attackers may be able to exploit this
vulnerability by creating a malicious certificate chain that triggers
exponential use of computational resources, leading to a denial-of-service
(DoS) attack on affected systems.
Policy processing is disabled by default but can be enabled by passing
the `-policy' argument to the command line utilities or by calling the
`X509_VERIFY_PARAM_set1_policies()' function.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: A type confusion vulnerability exists in the TimeStamp Response
verification code where an ASN1_TYPE union member is accessed without first
validating the type, causing an invalid or NULL pointer dereference when
processing a malformed TimeStamp Response file.
Impact summary: An application calling TS_RESP_verify_response() with a
malformed TimeStamp Response can be caused to dereference an invalid or
NULL pointer when reading, resulting in a Denial of Service.
The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2()
access the signing cert attribute value without validating its type.
When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory
through the ASN1_TYPE union, causing a crash.
Exploiting this vulnerability requires an attacker to provide a malformed
TimeStamp Response to an application that verifies timestamp responses. The
TimeStamp protocol (RFC 3161) is not widely used and the impact of the
exploit is just a Denial of Service. For these reasons the issue was
assessed as Low severity.
The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,
as the TimeStamp Response implementation is outside the OpenSSL FIPS module
boundary.
OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.
OpenSSL 1.0.2 is not affected by this issue.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer
dereference in the PKCS12_item_decrypt_d2i_ex() function.
Impact summary: A NULL pointer dereference can trigger a crash which leads to
Denial of Service for an application processing PKCS#12 files.
The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct
parameter is NULL before dereferencing it. When called from
PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can
be NULL, causing a crash. The vulnerability is limited to Denial of Service
and cannot be escalated to achieve code execution or memory disclosure.
Exploiting this issue requires an attacker to provide a malformed PKCS#12 file
to an application that processes it. For that reason the issue was assessed as
Low severity according to our Security Policy.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,
as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.
OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: When a delta CRL that contains a Delta CRL Indicator extension
is processed a NULL pointer dereference might happen if the required CRL
Number extension is missing.
Impact summary: A NULL pointer dereference can trigger a crash which
leads to a Denial of Service for an application.
When CRL processing and delta CRL processing is enabled during X.509
certificate verification, the delta CRL processing does not check
whether the CRL Number extension is NULL before dereferencing it.
When a malformed delta CRL file is being processed, this parameter
can be NULL, causing a NULL pointer dereference.
Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in
the verification context, the certificate being verified to contain a
freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and
an attacker to provide a malformed CRL to an application that processes it.
The vulnerability is limited to Denial of Service and cannot be escalated to
achieve code execution or memory disclosure. For that reason the issue was
assessed as Low severity according to our Security Policy.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,
as the affected code is outside the OpenSSL FIPS module boundary.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: During processing of a crafted CMS EnvelopedData message
with KeyAgreeRecipientInfo a NULL pointer dereference can happen.
Impact summary: Applications that process attacker-controlled CMS data may
crash before authentication or cryptographic operations occur resulting in
Denial of Service.
When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is
processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier
is examined without checking for its presence. This results in a NULL
pointer dereference if the field is missing.
Applications and services that call CMS_decrypt() on untrusted input
(e.g., S/MIME processing or CMS-based protocols) are vulnerable.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this
issue, as the affected code is outside the OpenSSL FIPS module boundary.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: During processing of a crafted CMS EnvelopedData message
with KeyTransportRecipientInfo a NULL pointer dereference can happen.
Impact summary: Applications that process attacker-controlled CMS data may
crash before authentication or cryptographic operations occur resulting in
Denial of Service.
When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with
RSA-OAEP encryption is processed, the optional parameters field of
RSA-OAEP SourceFunc algorithm identifier is examined without checking
for its presence. This results in a NULL pointer dereference if the field
is missing.
Applications and services that call CMS_decrypt() on untrusted input
(e.g., S/MIME processing or CMS-based protocols) are vulnerable.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this
issue, as the affected code is outside the OpenSSL FIPS module boundary.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive
element whose content exceeds 2 gigabytes in length may cause a heap buffer
over-read on 64-bit Unix and Unix-like platforms.
Impact summary: The heap buffer over-read may crash the application (Denial of
Service) or to load into the decoded ASN.1 object contents of memory beyond the
end of the input buffer. More typically such ASN.1 elements would instead be
truncated.
An integer truncation in OpenSSL's ASN.1 decoder causes the content length of
an ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the
worst case the truncated length is treated as a request to scan the binary
content for a terminating zero byte, possibly causing OpenSSL to read either
less than or beyond the end of the allocated buffer.
Applications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or
any other d2i_* decoding function are affected. OpenSSL's own command-line
tools are not vulnerable, as data read through the BIO layer is checked before
it reaches the affected code. The issue only affects 64-bit Unix and Unix-like
platforms; 32-bit platforms and 64-bit Windows are not affected.
The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue,
as the affected code is outside the OpenSSL FIPS module boundary.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)
processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK
cipher can trigger a heap out-of-bounds read in kek_unwrap_key().
Impact summary: A heap buffer over-read may trigger a crash which leads to
Denial of Service for an application if the input buffer ends at a memory
page boundary and the following page is unmapped. There is no information
disclosure as the over-read bytes are not revealed to the attacker.
The key unwrapping function performs a check-byte test as specified in the
RFC that reads 7 bytes from a heap allocation that is based on the wrapped
key length from the message. There is a minimum length check based on the
block length of the wrapping cipher. However the cipher is selected from
an OID carried in the attacker's PWRI keyEncryptionAlgorithm with no
requirement that the cipher be a block cipher. When an attacker selects
a stream-mode cipher the guard will be ineffective and the allocated buffer
containing the unwrapped key can be too small to fit the check-bytes
specified in the RFC and a buffer over-read can happen.
Applications calling CMS_decrypt() or CMS_decrypt_set1_password()
(equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS
data are vulnerable to this issue. No password knowledge is required: the
over-read happens during the unwrap attempt before any authentication
succeeds.
The over-read is limited to a few bytes and is not written to output, so
there is no information disclosure. Triggering a crash requires the
allocation to border unmapped memory, which is unlikely with the normal
allocator.
The FIPS modules are not affected by this issue.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a strict requirement, ASN.1 strings that are parsed using OpenSSL's own "d2i" functions (and other similar parsing functions) as well as any string whose value has been set with the ASN1_STRING_set() function will additionally NUL terminate the byte array in the ASN1_STRING structure. However, it is possible for applications to directly construct valid ASN1_STRING structures which do not NUL terminate the byte array by directly setting the "data" and "length" fields in the ASN1_STRING array. This can also happen by using the ASN1_STRING_set0() function. Numerous OpenSSL functions that print ASN.1 data have been found to assume that the ASN1_STRING byte array will be NUL terminated, even though this is not guaranteed for strings that have been directly constructed. Where an application requests an ASN.1 structure to be printed, and where that ASN.1 structure contains ASN1_STRINGs that have been directly constructed by the application without NUL terminating the "data" field, then a read buffer overrun can occur. The same thing can also occur during name constraints processing of certificates (for example if a certificate has been directly constructed by the application instead of loading it via the OpenSSL parsing functions, and the certificate contains non NUL terminated ASN1_STRING structures). It can also occur in the X509_get1_email(), X509_REQ_get1_email() and X509_get1_ocsp() functions. If a malicious actor can cause an application to directly construct an ASN1_STRING and then process it through one of the affected OpenSSL functions then this issue could be hit. This might result in a crash (causing a Denial of Service attack). It could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext). Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k). Fixed in OpenSSL 1.0.2za (Affected 1.0.2-1.0.2y).
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
There is a type confusion vulnerability relating to X.400 address processing
inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but
the public structure definition for GENERAL_NAME incorrectly specified the type
of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by
the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an
ASN1_STRING.
When CRL checking is enabled (i.e. the application sets the
X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass
arbitrary pointers to a memcmp call, enabling them to read memory contents or
enact a denial of service. In most cases, the attack requires the attacker to
provide both the certificate chain and CRL, neither of which need to have a
valid signature. If the attacker only controls one of these inputs, the other
input must already contain an X.400 address as a CRL distribution point, which
is uncommon. As such, this vulnerability is most likely to only affect
applications which have implemented their own functionality for retrieving CRLs
over a network.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously
crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing
non-ASCII BMP code point can trigger a one byte write before the allocated
buffer.
Impact summary: The out-of-bounds write can cause a memory corruption
which can have various consequences including a Denial of Service.
The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12
BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes,
the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16
source byte count as the destination buffer capacity to UTF8_putc(). For BMP
code points above U+07FF, UTF-8 requires three bytes, but the forwarded
capacity can be just two bytes. UTF8_putc() then returns -1, and this negative
value is added to the output length without validation, causing the
length to become negative. The subsequent trailing NUL byte is then written
at a negative offset, causing write outside of heap allocated buffer.
The vulnerability is reachable via the public PKCS12_get_friendlyname() API
when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a
different code path that avoids this issue, PKCS12_get_friendlyname() directly
invokes the vulnerable function. Exploitation requires an attacker to provide
a malicious PKCS#12 file to be parsed by the application and the attacker
can just trigger a one zero byte write before the allocated buffer.
For that reason the issue was assessed as Low severity according to our
Security Policy.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,
as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.
OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.
OpenSSL 1.0.2 is not affected by this issue.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd).
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0.0,3.0.1,3.0.2,3.0.3). Fixed in OpenSSL 1.1.1p (Affected 1.1.1-1.1.1o). Fixed in OpenSSL 1.0.2zf (Affected 1.0.2-1.0.2ze).
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: Processing some specially crafted ASN.1 object identifiers or
data containing them may be very slow.
Impact summary: Applications that use OBJ_obj2txt() directly, or use any of
the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message
size limit may experience notable to very long delays when processing those
messages, which may lead to a Denial of Service.
An OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers -
most of which have no size limit. OBJ_obj2txt() may be used to translate
an ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL
type ASN1_OBJECT) to its canonical numeric text form, which are the
sub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by
periods.
When one of the sub-identifiers in the OBJECT IDENTIFIER is very large
(these are sizes that are seen as absurdly large, taking up tens or hundreds
of KiBs), the translation to a decimal number in text may take a very long
time. The time complexity is O(n^2) with 'n' being the size of the
sub-identifiers in bytes (*).
With OpenSSL 3.0, support to fetch cryptographic algorithms using names /
identifiers in string form was introduced. This includes using OBJECT
IDENTIFIERs in canonical numeric text form as identifiers for fetching
algorithms.
Such OBJECT IDENTIFIERs may be received through the ASN.1 structure
AlgorithmIdentifier, which is commonly used in multiple protocols to specify
what cryptographic algorithm should be used to sign or verify, encrypt or
decrypt, or digest passed data.
Applications that call OBJ_obj2txt() directly with untrusted data are
affected, with any version of OpenSSL. If the use is for the mere purpose
of display, the severity is considered low.
In OpenSSL 3.0 and newer, this affects the subsystems OCSP, PKCS7/SMIME,
CMS, CMP/CRMF or TS. It also impacts anything that processes X.509
certificates, including simple things like verifying its signature.
The impact on TLS is relatively low, because all versions of OpenSSL have a
100KiB limit on the peer's certificate chain. Additionally, this only
impacts clients, or servers that have explicitly enabled client
authentication.
In OpenSSL 1.1.1 and 1.0.2, this only affects displaying diverse objects,
such as X.509 certificates. This is assumed to not happen in such a way
that it would cause a Denial of Service, so these versions are considered
not affected by this issue in such a way that it would be cause for concern,
and the severity is therefore considered low.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
A timing based side channel exists in the OpenSSL RSA Decryption implementation
which could be sufficient to recover a plaintext across a network in a
Bleichenbacher style attack. To achieve a successful decryption an attacker
would have to be able to send a very large number of trial messages for
decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5,
RSA-OEAP and RSASVE.
For example, in a TLS connection, RSA is commonly used by a client to send an
encrypted pre-master secret to the server. An attacker that had observed a
genuine connection between a client and a server could use this flaw to send
trial messages to the server and record the time taken to process them. After a
sufficiently large number of messages the attacker could recover the pre-master
secret used for the original connection and thus be able to decrypt the
application data sent over that connection.
Hệ thống tìm thấy 44 kết quả tiềm năng cho sản phẩm này, nhưng báo cáo chỉ lưu một phần chi tiết đại diện.
CVE-2024-38475
HTTPD 2.4.41
KEVCVSS 9,1
Sản phẩm đối chiếu: HTTPD 2.4.41 Độ tin cậy: Cao
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.
Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected. Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.
Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack.
Configurations are affected when mod_proxy is enabled along with some form of RewriteRule
or ProxyPassMatch in which a non-specific pattern matches
some portion of the user-supplied request-target (URL) data and is then
re-inserted into the proxied request-target using variable
substitution. For example, something like:
RewriteEngine on
RewriteRule "^/here/(.*)" "http://example.com:8080/elsewhere?$1"; [P]
ProxyPassReverse /here/ http://example.com:8080/
Request splitting/smuggling could result in bypass of access controls in the proxy server, proxying unintended URLs to existing origin servers, and cache poisoning. Users are recommended to update to at least version 2.4.56 of Apache HTTP Server.
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in
directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.
Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may hypothetically be affected.
In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption.
Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of trusted client certificates (for example with a different SSLCACertificateFile/Path setting). In such a case, a client trusted to access one virtual host may be able to access another virtual host, if SSLStrictSNIVHostCheck is not enabled in either virtual host.
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.54 and prior versions.
An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
Users are recommended to upgrade to version 2.4.67, which fixes this issue.
Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives.
This issue affects Apache HTTP Server before 2.4.66.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
Hệ thống tìm thấy 83 kết quả tiềm năng cho sản phẩm này, nhưng báo cáo chỉ lưu một phần chi tiết đại diện.
CVE-2020-11023jquery 2.2.4KEVCVSS 6,1
Sản phẩm đối chiếu: jquery 2.2.4 Độ tin cậy: Cao
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the decrypted plaintext. The application can then allocate a sufficiently sized buffer and call EVP_PKEY_decrypt() again, but this time passing a non-NULL value for the "out" parameter. A bug in the implementation of the SM2 decryption code means that the calculation of the buffer size required to hold the plaintext returned by the first call to EVP_PKEY_decrypt() can be smaller than the actual size required by the second call. This can lead to a buffer overflow when EVP_PKEY_decrypt() is called by the application a second time with a buffer that is too small. A malicious attacker who is able present SM2 content for decryption to an application could cause attacker chosen data to overflow the buffer by up to a maximum of 62 bytes altering the contents of other data held after the buffer, possibly changing application behaviour or causing the application to crash. The location of the buffer is application dependent but is typically heap allocated. Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k).
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could
trigger a use-after-free during PKCS#7 signature verification.
Impact summary: A use-after-free may result in process crashes, heap
corruption, or potentially remote code execution.
When processing a PKCS#7 or S/MIME signed message, if the SignedData
digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may
incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent
use of the BIO by the calling application results in a use-after-free
condition.
In the common case this occurs when the application later calls
BIO_free() on the BIO originally passed to PKCS7_verify(). Depending
on allocator behavior and application-specific BIO usage patterns, this
may result in a crash or other memory corruption. In some application
contexts this may potentially be exploitable for remote code execution.
Applications that process PKCS#7 or S/MIME signed messages using OpenSSL
PKCS#7 APIs may be affected. Applications using the CMS APIs for this
processing are not affected.
The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this
issue, as the affected code is outside the OpenSSL FIPS module boundary.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: An uncommon configuration of clients performing DANE TLSA-based
server authentication, when paired with uncommon server DANE TLSA records, may
result in a use-after-free and/or double-free on the client side.
Impact summary: A use after free can have a range of potential consequences
such as the corruption of valid data, crashes or execution of arbitrary code.
However, the issue only affects clients that make use of TLSA records with both
the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate
usage.
By far the most common deployment of DANE is in SMTP MTAs for which RFC7672
recommends that clients treat as 'unusable' any TLSA records that have the PKIX
certificate usages. These SMTP (or other similar) clients are not vulnerable
to this issue. Conversely, any clients that support only the PKIX usages, and
ignore the DANE-TA(2) usage are also not vulnerable.
The client would also need to be communicating with a server that publishes a
TLSA RRset with both types of TLSA records.
No FIPS modules are affected by this issue, the problem code is outside the
FIPS module boundary.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: A signed integer overflow when sizing the destination
buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap
buffer overflow.
Impact summary: A heap buffer overflow may lead to a crash or possibly
attacker controlled code execution or other undefined behaviour.
In ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination
size for Unicode output is computed in a signed int: by left shift
of the input character count for BMPSTRING (UTF-16) and
UNIVERSALSTRING (UTF-32), and by summing per-character byte counts
for UTF8STRING. The calculation overflows when the input reaches
around 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30
characters) the size wraps to zero, OPENSSL_malloc(1) is called, and
the subsequent character copy writes several gigabytes past the
one-byte allocation.
X.509 certificate processing routes through ASN1_STRING_set_by_NID(),
whose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID
size limits cap the input length; no network protocol or
certificate-handling path in OpenSSL exercises the overflow.
Triggering the bug requires an application that calls
ASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers
a custom string type via ASN1_STRING_TABLE_add(), with
attacker-controlled input on the order of half a gigabyte or more.
For these reasons this issue was assigned Low severity.
The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by
this issue, as the affected code is outside the OpenSSL FIPS module
boundary.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: The POLY1305 MAC (message authentication code) implementation
contains a bug that might corrupt the internal state of applications on the
Windows 64 platform when running on newer X86_64 processors supporting the
AVX512-IFMA instructions.
Impact summary: If in an application that uses the OpenSSL library an attacker
can influence whether the POLY1305 MAC algorithm is used, the application
state might be corrupted with various application dependent consequences.
The POLY1305 MAC (message authentication code) implementation in OpenSSL does
not save the contents of non-volatile XMM registers on Windows 64 platform
when calculating the MAC of data larger than 64 bytes. Before returning to
the caller all the XMM registers are set to zero rather than restoring their
previous content. The vulnerable code is used only on newer x86_64 processors
supporting the AVX512-IFMA instructions.
The consequences of this kind of internal application state corruption can
be various - from no consequences, if the calling application does not
depend on the contents of non-volatile XMM registers at all, to the worst
consequences, where the attacker could get complete control of the application
process. However given the contents of the registers are just zeroized so
the attacker cannot put arbitrary values inside, the most likely consequence,
if any, would be an incorrect result of some application dependent
calculations or a crash leading to a denial of service.
The POLY1305 MAC algorithm is most frequently used as part of the
CHACHA20-POLY1305 AEAD (authenticated encryption with associated data)
algorithm. The most common usage of this AEAD cipher is with TLS protocol
versions 1.2 and 1.3 and a malicious client can influence whether this AEAD
cipher is used by the server. This implies that server applications using
OpenSSL can be potentially impacted. However we are currently not aware of
any concrete application that would be affected by this issue therefore we
consider this a Low severity security issue.
As a workaround the AVX512-IFMA instructions support can be disabled at
runtime by setting the environment variable OPENSSL_ia32cap:
OPENSSL_ia32cap=:~0x200000
The FIPS provider is not affected by this issue.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022. Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc).
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and
decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data.
If the function succeeds then the "name_out", "header" and "data" arguments are
populated with pointers to buffers containing the relevant decoded data. The
caller is responsible for freeing those buffers. It is possible to construct a
PEM file that results in 0 bytes of payload data. In this case PEM_read_bio_ex()
will return a failure code but will populate the header argument with a pointer
to a buffer that has already been freed. If the caller also frees this buffer
then a double free will occur. This will most likely lead to a crash. This
could be exploited by an attacker who has the ability to supply malicious PEM
files for parsing to achieve a denial of service attack.
The functions PEM_read_bio() and PEM_read() are simple wrappers around
PEM_read_bio_ex() and therefore these functions are also directly affected.
These functions are also called indirectly by a number of other OpenSSL
functions including PEM_X509_INFO_read_bio_ex() and
SSL_CTX_use_serverinfo_file() which are also vulnerable. Some OpenSSL internal
uses of these functions are not vulnerable because the caller does not free the
header argument if PEM_read_bio_ex() returns a failure code. These locations
include the PEM_read_bio_TYPE() functions as well as the decoders introduced in
OpenSSL 3.0.
The OpenSSL asn1parse command line application is also impacted by this issue.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
The public API function BIO_new_NDEF is a helper function used for streaming
ASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the
SMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by
end user applications.
The function receives a BIO from the caller, prepends a new BIO_f_asn1 filter
BIO onto the front of it to form a BIO chain, and then returns the new head of
the BIO chain to the caller. Under certain conditions, for example if a CMS
recipient public key is invalid, the new filter BIO is freed and the function
returns a NULL result indicating a failure. However, in this case, the BIO chain
is not properly cleaned up and the BIO passed by the caller still retains
internal pointers to the previously freed filter BIO. If the caller then goes on
to call BIO_pop() on the BIO then a use-after-free will occur. This will most
likely result in a crash.
This scenario occurs directly in the internal function B64_write_ASN1() which
may cause BIO_new_NDEF() to be called and will subsequently call BIO_pop() on
the BIO. This internal function is in turn called by the public API functions
PEM_write_bio_ASN1_stream, PEM_write_bio_CMS_stream, PEM_write_bio_PKCS7_stream,
SMIME_write_ASN1, SMIME_write_CMS and SMIME_write_PKCS7.
Other public API functions that may be impacted by this include
i2d_ASN1_bio_stream, BIO_new_CMS, BIO_new_PKCS7, i2d_CMS_bio_stream and
i2d_PKCS7_bio_stream.
The OpenSSL cms and smime command line applications are similarly affected.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
A security vulnerability has been identified in all supported versions
of OpenSSL related to the verification of X.509 certificate chains
that include policy constraints. Attackers may be able to exploit this
vulnerability by creating a malicious certificate chain that triggers
exponential use of computational resources, leading to a denial-of-service
(DoS) attack on affected systems.
Policy processing is disabled by default but can be enabled by passing
the `-policy' argument to the command line utilities or by calling the
`X509_VERIFY_PARAM_set1_policies()' function.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: A type confusion vulnerability exists in the TimeStamp Response
verification code where an ASN1_TYPE union member is accessed without first
validating the type, causing an invalid or NULL pointer dereference when
processing a malformed TimeStamp Response file.
Impact summary: An application calling TS_RESP_verify_response() with a
malformed TimeStamp Response can be caused to dereference an invalid or
NULL pointer when reading, resulting in a Denial of Service.
The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2()
access the signing cert attribute value without validating its type.
When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory
through the ASN1_TYPE union, causing a crash.
Exploiting this vulnerability requires an attacker to provide a malformed
TimeStamp Response to an application that verifies timestamp responses. The
TimeStamp protocol (RFC 3161) is not widely used and the impact of the
exploit is just a Denial of Service. For these reasons the issue was
assessed as Low severity.
The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,
as the TimeStamp Response implementation is outside the OpenSSL FIPS module
boundary.
OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.
OpenSSL 1.0.2 is not affected by this issue.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer
dereference in the PKCS12_item_decrypt_d2i_ex() function.
Impact summary: A NULL pointer dereference can trigger a crash which leads to
Denial of Service for an application processing PKCS#12 files.
The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct
parameter is NULL before dereferencing it. When called from
PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can
be NULL, causing a crash. The vulnerability is limited to Denial of Service
and cannot be escalated to achieve code execution or memory disclosure.
Exploiting this issue requires an attacker to provide a malformed PKCS#12 file
to an application that processes it. For that reason the issue was assessed as
Low severity according to our Security Policy.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,
as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.
OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: When a delta CRL that contains a Delta CRL Indicator extension
is processed a NULL pointer dereference might happen if the required CRL
Number extension is missing.
Impact summary: A NULL pointer dereference can trigger a crash which
leads to a Denial of Service for an application.
When CRL processing and delta CRL processing is enabled during X.509
certificate verification, the delta CRL processing does not check
whether the CRL Number extension is NULL before dereferencing it.
When a malformed delta CRL file is being processed, this parameter
can be NULL, causing a NULL pointer dereference.
Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in
the verification context, the certificate being verified to contain a
freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and
an attacker to provide a malformed CRL to an application that processes it.
The vulnerability is limited to Denial of Service and cannot be escalated to
achieve code execution or memory disclosure. For that reason the issue was
assessed as Low severity according to our Security Policy.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,
as the affected code is outside the OpenSSL FIPS module boundary.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: During processing of a crafted CMS EnvelopedData message
with KeyAgreeRecipientInfo a NULL pointer dereference can happen.
Impact summary: Applications that process attacker-controlled CMS data may
crash before authentication or cryptographic operations occur resulting in
Denial of Service.
When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is
processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier
is examined without checking for its presence. This results in a NULL
pointer dereference if the field is missing.
Applications and services that call CMS_decrypt() on untrusted input
(e.g., S/MIME processing or CMS-based protocols) are vulnerable.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this
issue, as the affected code is outside the OpenSSL FIPS module boundary.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: During processing of a crafted CMS EnvelopedData message
with KeyTransportRecipientInfo a NULL pointer dereference can happen.
Impact summary: Applications that process attacker-controlled CMS data may
crash before authentication or cryptographic operations occur resulting in
Denial of Service.
When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with
RSA-OAEP encryption is processed, the optional parameters field of
RSA-OAEP SourceFunc algorithm identifier is examined without checking
for its presence. This results in a NULL pointer dereference if the field
is missing.
Applications and services that call CMS_decrypt() on untrusted input
(e.g., S/MIME processing or CMS-based protocols) are vulnerable.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this
issue, as the affected code is outside the OpenSSL FIPS module boundary.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive
element whose content exceeds 2 gigabytes in length may cause a heap buffer
over-read on 64-bit Unix and Unix-like platforms.
Impact summary: The heap buffer over-read may crash the application (Denial of
Service) or to load into the decoded ASN.1 object contents of memory beyond the
end of the input buffer. More typically such ASN.1 elements would instead be
truncated.
An integer truncation in OpenSSL's ASN.1 decoder causes the content length of
an ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the
worst case the truncated length is treated as a request to scan the binary
content for a terminating zero byte, possibly causing OpenSSL to read either
less than or beyond the end of the allocated buffer.
Applications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or
any other d2i_* decoding function are affected. OpenSSL's own command-line
tools are not vulnerable, as data read through the BIO layer is checked before
it reaches the affected code. The issue only affects 64-bit Unix and Unix-like
platforms; 32-bit platforms and 64-bit Windows are not affected.
The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue,
as the affected code is outside the OpenSSL FIPS module boundary.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)
processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK
cipher can trigger a heap out-of-bounds read in kek_unwrap_key().
Impact summary: A heap buffer over-read may trigger a crash which leads to
Denial of Service for an application if the input buffer ends at a memory
page boundary and the following page is unmapped. There is no information
disclosure as the over-read bytes are not revealed to the attacker.
The key unwrapping function performs a check-byte test as specified in the
RFC that reads 7 bytes from a heap allocation that is based on the wrapped
key length from the message. There is a minimum length check based on the
block length of the wrapping cipher. However the cipher is selected from
an OID carried in the attacker's PWRI keyEncryptionAlgorithm with no
requirement that the cipher be a block cipher. When an attacker selects
a stream-mode cipher the guard will be ineffective and the allocated buffer
containing the unwrapped key can be too small to fit the check-bytes
specified in the RFC and a buffer over-read can happen.
Applications calling CMS_decrypt() or CMS_decrypt_set1_password()
(equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS
data are vulnerable to this issue. No password knowledge is required: the
over-read happens during the unwrap attempt before any authentication
succeeds.
The over-read is limited to a few bytes and is not written to output, so
there is no information disclosure. Triggering a crash requires the
allocation to border unmapped memory, which is unlikely with the normal
allocator.
The FIPS modules are not affected by this issue.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a strict requirement, ASN.1 strings that are parsed using OpenSSL's own "d2i" functions (and other similar parsing functions) as well as any string whose value has been set with the ASN1_STRING_set() function will additionally NUL terminate the byte array in the ASN1_STRING structure. However, it is possible for applications to directly construct valid ASN1_STRING structures which do not NUL terminate the byte array by directly setting the "data" and "length" fields in the ASN1_STRING array. This can also happen by using the ASN1_STRING_set0() function. Numerous OpenSSL functions that print ASN.1 data have been found to assume that the ASN1_STRING byte array will be NUL terminated, even though this is not guaranteed for strings that have been directly constructed. Where an application requests an ASN.1 structure to be printed, and where that ASN.1 structure contains ASN1_STRINGs that have been directly constructed by the application without NUL terminating the "data" field, then a read buffer overrun can occur. The same thing can also occur during name constraints processing of certificates (for example if a certificate has been directly constructed by the application instead of loading it via the OpenSSL parsing functions, and the certificate contains non NUL terminated ASN1_STRING structures). It can also occur in the X509_get1_email(), X509_REQ_get1_email() and X509_get1_ocsp() functions. If a malicious actor can cause an application to directly construct an ASN1_STRING and then process it through one of the affected OpenSSL functions then this issue could be hit. This might result in a crash (causing a Denial of Service attack). It could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext). Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k). Fixed in OpenSSL 1.0.2za (Affected 1.0.2-1.0.2y).
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
There is a type confusion vulnerability relating to X.400 address processing
inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but
the public structure definition for GENERAL_NAME incorrectly specified the type
of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by
the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an
ASN1_STRING.
When CRL checking is enabled (i.e. the application sets the
X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass
arbitrary pointers to a memcmp call, enabling them to read memory contents or
enact a denial of service. In most cases, the attack requires the attacker to
provide both the certificate chain and CRL, neither of which need to have a
valid signature. If the attacker only controls one of these inputs, the other
input must already contain an X.400 address as a CRL distribution point, which
is uncommon. As such, this vulnerability is most likely to only affect
applications which have implemented their own functionality for retrieving CRLs
over a network.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously
crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing
non-ASCII BMP code point can trigger a one byte write before the allocated
buffer.
Impact summary: The out-of-bounds write can cause a memory corruption
which can have various consequences including a Denial of Service.
The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12
BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes,
the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16
source byte count as the destination buffer capacity to UTF8_putc(). For BMP
code points above U+07FF, UTF-8 requires three bytes, but the forwarded
capacity can be just two bytes. UTF8_putc() then returns -1, and this negative
value is added to the output length without validation, causing the
length to become negative. The subsequent trailing NUL byte is then written
at a negative offset, causing write outside of heap allocated buffer.
The vulnerability is reachable via the public PKCS12_get_friendlyname() API
when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a
different code path that avoids this issue, PKCS12_get_friendlyname() directly
invokes the vulnerable function. Exploitation requires an attacker to provide
a malicious PKCS#12 file to be parsed by the application and the attacker
can just trigger a one zero byte write before the allocated buffer.
For that reason the issue was assessed as Low severity according to our
Security Policy.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,
as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.
OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.
OpenSSL 1.0.2 is not affected by this issue.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd).
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0.0,3.0.1,3.0.2,3.0.3). Fixed in OpenSSL 1.1.1p (Affected 1.1.1-1.1.1o). Fixed in OpenSSL 1.0.2zf (Affected 1.0.2-1.0.2ze).
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
Issue summary: Processing some specially crafted ASN.1 object identifiers or
data containing them may be very slow.
Impact summary: Applications that use OBJ_obj2txt() directly, or use any of
the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message
size limit may experience notable to very long delays when processing those
messages, which may lead to a Denial of Service.
An OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers -
most of which have no size limit. OBJ_obj2txt() may be used to translate
an ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL
type ASN1_OBJECT) to its canonical numeric text form, which are the
sub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by
periods.
When one of the sub-identifiers in the OBJECT IDENTIFIER is very large
(these are sizes that are seen as absurdly large, taking up tens or hundreds
of KiBs), the translation to a decimal number in text may take a very long
time. The time complexity is O(n^2) with 'n' being the size of the
sub-identifiers in bytes (*).
With OpenSSL 3.0, support to fetch cryptographic algorithms using names /
identifiers in string form was introduced. This includes using OBJECT
IDENTIFIERs in canonical numeric text form as identifiers for fetching
algorithms.
Such OBJECT IDENTIFIERs may be received through the ASN.1 structure
AlgorithmIdentifier, which is commonly used in multiple protocols to specify
what cryptographic algorithm should be used to sign or verify, encrypt or
decrypt, or digest passed data.
Applications that call OBJ_obj2txt() directly with untrusted data are
affected, with any version of OpenSSL. If the use is for the mere purpose
of display, the severity is considered low.
In OpenSSL 3.0 and newer, this affects the subsystems OCSP, PKCS7/SMIME,
CMS, CMP/CRMF or TS. It also impacts anything that processes X.509
certificates, including simple things like verifying its signature.
The impact on TLS is relatively low, because all versions of OpenSSL have a
100KiB limit on the peer's certificate chain. Additionally, this only
impacts clients, or servers that have explicitly enabled client
authentication.
In OpenSSL 1.1.1 and 1.0.2, this only affects displaying diverse objects,
such as X.509 certificates. This is assumed to not happen in such a way
that it would cause a Denial of Service, so these versions are considered
not affected by this issue in such a way that it would be cause for concern,
and the severity is therefore considered low.
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).
Sản phẩm đối chiếu: openssl 1.1.1c Độ tin cậy: Cao
A timing based side channel exists in the OpenSSL RSA Decryption implementation
which could be sufficient to recover a plaintext across a network in a
Bleichenbacher style attack. To achieve a successful decryption an attacker
would have to be able to send a very large number of trial messages for
decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5,
RSA-OEAP and RSASVE.
For example, in a TLS connection, RSA is commonly used by a client to send an
encrypted pre-master secret to the server. An attacker that had observed a
genuine connection between a client and a server could use this flaw to send
trial messages to the server and record the time taken to process them. After a
sufficiently large number of messages the attacker could recover the pre-master
secret used for the original connection and thus be able to decrypt the
application data sent over that connection.