{"id":46213,"date":"2025-05-28T17:20:05","date_gmt":"2025-05-28T10:20:05","guid":{"rendered":"https:\/\/antoanthongtinhaiphong.gov.vn\/?p=46213"},"modified":"2025-06-10T17:21:13","modified_gmt":"2025-06-10T10:21:13","slug":"lo-hong-sso-nghiem-trong-cua-samlify-cho-phep-ke-tan-cong-dang-nhap-voi-tu-cach-quan-tri-vien","status":"publish","type":"post","link":"https:\/\/antoanthongtinhaiphong.gov.vn\/lo-hong-sso-nghiem-trong-cua-samlify-cho-phep-ke-tan-cong-dang-nhap-voi-tu-cach-quan-tri-vien\/","title":{"rendered":"L\u1ed7 h\u1ed5ng SSO nghi\u00eam tr\u1ecdng c\u1ee7a Samlify cho ph\u00e9p k\u1ebb t\u1ea5n c\u00f4ng \u0111\u0103ng nh\u1eadp v\u1edbi t\u01b0 c\u00e1ch qu\u1ea3n tr\u1ecb vi\u00ean"},"content":{"rendered":"<p class=\"mt-3 excerpt\">M\u1ed9t l\u1ed7 h\u1ed5ng x\u00e1c th\u1ef1c Samlify quan tr\u1ecdng \u0111\u00e3 \u0111\u01b0\u1ee3c c\u00e1c nh\u00e0 nghi\u00ean c\u1ee9u c\u1ee7a c\u00f4ng ty an ninh m\u1ea1ng EndorLabs (M\u1ef9) ph\u00e1t hi\u1ec7n, cho ph\u00e9p k\u1ebb t\u1ea5n c\u00f4ng m\u1ea1o danh ng\u01b0\u1eddi d\u00f9ng qu\u1ea3n tr\u1ecb b\u1eb1ng c\u00e1ch \u0111\u01b0a c\u00e1c x\u00e1c nh\u1eadn \u0111\u1ed9c h\u1ea1i v\u00e0o c\u00e1c response SAML \u0111\u00e3 \u0111\u01b0\u1ee3c k\u00fd s\u1ed1 h\u1ee3p l\u1ec7.<\/p>\n<div id=\"relatedPost\" class=\"mt-3 mb-3\">\n<div class=\"\">\n<ul class=\"ms-2\">\n<li class=\"d-flex\">\n<ul class=\"d-flex flex-column gap-2\">\n<li class=\"title bullet\" title=\"Ph\u00e1t hi\u1ec7n 40 l\u1ed7 h\u1ed5ng khi di\u1ec5n t\u1eadp th\u1ef1c chi\u1ebfn \u1ee9ng ph\u00f3, kh\u1eafc ph\u1ee5c s\u1ef1 c\u1ed1 an ninh m\u1ea1ng\">Ph\u00e1t hi\u1ec7n 40 l\u1ed7 h\u1ed5ng khi di\u1ec5n t\u1eadp th\u1ef1c chi\u1ebfn \u1ee9ng ph\u00f3, kh\u1eafc ph\u1ee5c s\u1ef1 c\u1ed1 an ninh m\u1ea1ng<\/li>\n<\/ul>\n<\/li>\n<li class=\"d-flex\">\n<ul class=\"d-flex flex-column gap-2\">\n<li class=\"title bullet\" title=\"L\u1ed7 h\u1ed5ng ASUS DriverHub cho ph\u00e9p c\u00e1c trang web \u0111\u1ed9c h\u1ea1i ch\u1ea1y l\u1ec7nh v\u1edbi quy\u1ec1n qu\u1ea3n tr\u1ecb vi\u00ean\">L\u1ed7 h\u1ed5ng ASUS DriverHub cho ph\u00e9p c\u00e1c trang web \u0111\u1ed9c h\u1ea1i ch\u1ea1y l\u1ec7nh v\u1edbi quy\u1ec1n qu\u1ea3n tr\u1ecb vi\u00ean<\/li>\n<\/ul>\n<\/li>\n<li class=\"d-flex\">\n<ul class=\"d-flex flex-column gap-2\">\n<li class=\"title bullet\" title=\"SAP v\u00e1 l\u1ed7 h\u1ed5ng zero-day th\u1ee9 hai b\u1ecb khai th\u00e1c trong c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng g\u1ea7n \u0111\u00e2y\">SAP v\u00e1 l\u1ed7 h\u1ed5ng zero-day th\u1ee9 hai b\u1ecb khai th\u00e1c trong c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng g\u1ea7n \u0111\u00e2y<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<article id=\"content\" class=\"content gradient\"><img decoding=\"async\" src=\"https:\/\/dulieu.antoanthongtin.gov.vn\/tapchiantoanthongtin\/4c94532f-5e28-4ead-9a91-4c79912d5453\/login-prompt.png\" \/><\/p>\n<p>Samlify l\u00e0 m\u1ed9t th\u01b0 vi\u1ec7n x\u00e1c th\u1ef1c gi\u00fap c\u00e1c nh\u00e0 ph\u00e1t tri\u1ec3n t\u00edch h\u1ee3p SAML SSO v\u00e0 Single Log-Out (SLO) v\u00e0o c\u00e1c \u1ee9ng d\u1ee5ng Node.js. \u0110\u00e2y l\u00e0 m\u1ed9t c\u00f4ng c\u1ee5 ph\u1ed5 bi\u1ebfn \u0111\u1ec3 x\u00e2y d\u1ef1ng ho\u1eb7c k\u1ebft n\u1ed1i v\u1edbi c\u00e1c nh\u00e0 cung c\u1ea5p \u0111\u1ecbnh danh (IdP) v\u00e0 nh\u00e0 cung c\u1ea5p d\u1ecbch v\u1ee5 (SP) b\u1eb1ng SAML.<\/p>\n<p>Th\u01b0 vi\u1ec7n \u0111\u01b0\u1ee3c s\u1eed d\u1ee5ng b\u1edfi c\u00e1c n\u1ec1n t\u1ea3ng SaaS, c\u00e1c t\u1ed5 ch\u1ee9c tri\u1ec3n khai SSO cho c\u00e1c c\u00f4ng c\u1ee5 n\u1ed9i b\u1ed9, c\u00e1c nh\u00e0 ph\u00e1t tri\u1ec3n t\u00edch h\u1ee3p v\u1edbi IdP nh\u01b0\u00a0<a href=\"https:\/\/antoanthongtin.vn\/tin\/nhieu-lo-hong-nghiem-trong-anh-huong-den-khach-hang-su-dung-azure\">Azure<\/a>\u00a0AD ho\u1eb7c Okta. Th\u01b0 vi\u1ec7n n\u00e0y r\u1ea5t ph\u1ed5 bi\u1ebfn, \u0111\u1ea1t h\u01a1n 200.000 l\u01b0\u1ee3t t\u1ea3i xu\u1ed1ng h\u00e0ng tu\u1ea7n tr\u00ean\u00a0<a href=\"https:\/\/antoanthongtin.vn\/tin\/cuoc-tan-cong-chuoi-cung-ung-moi-xam-pham-den-goi-npm-pho-bien-voi-45000-luot-tai-xuong-hang-tuan\">npm<\/a>.<\/p>\n<p>L\u1ed7 h\u1ed5ng n\u00e0y \u0111\u01b0\u1ee3c theo d\u00f5i v\u1edbi t\u00ean g\u1ecdi CVE-2025-47949, \u0111\u01b0\u1ee3c \u0111\u00e1nh gi\u00e1 nghi\u00eam tr\u1ecdng (\u0111i\u1ec3m CVSS v4.0: 9.9) \u1ea3nh h\u01b0\u1edfng \u0111\u1ebfn t\u1ea5t c\u1ea3 c\u00e1c phi\u00ean b\u1ea3n Samlify tr\u01b0\u1edbc 2.10.0. Theo c\u00e1c nh\u00e0 nghi\u00ean c\u1ee9u, Samlify x\u00e1c minh \u0111\u00fang r\u1eb1ng t\u00e0i li\u1ec7u XML cung c\u1ea5p \u0111\u1ecbnh danh c\u1ee7a ng\u01b0\u1eddi d\u00f9ng \u0111\u00e3 \u0111\u01b0\u1ee3c k\u00fd. Tuy nhi\u00ean, n\u00f3 v\u1eabn ti\u1ebfp t\u1ee5c \u0111\u1ecdc c\u00e1c Assertions (SAML Assertions ch\u1ee9a th\u00f4ng tin v\u1ec1 ng\u01b0\u1eddi d\u00f9ng, quy\u1ec1n truy c\u1eadp v\u00e0 c\u00e1c thu\u1ed9c t\u00ednh kh\u00e1c) gi\u1ea3 m\u1ea1o t\u1eeb m\u1ed9t ph\u1ea7n c\u1ee7a XML kh\u00f4ng \u0111\u01b0\u1ee3c k\u00fd.<\/p>\n<p>K\u1ebb t\u1ea5n c\u00f4ng n\u1eafm gi\u1eef response\u00a0<a href=\"https:\/\/antoanthongtin.vn\/tin\/lo-hong-trong-bypass-saml-cho-phep-ke-tan-cong-bo-qua-co-che-xac-thuc\">SAML<\/a>\u00a0\u0111\u00e3 k\u00fd s\u1ed1 h\u1ee3p l\u1ec7 th\u00f4ng qua vi\u1ec7c ng\u0103n ch\u1eb7n ho\u1eb7c metadata c\u00f4ng khai c\u00f3 th\u1ec3 s\u1eeda \u0111\u1ed5i response \u0111\u00f3 \u0111\u1ec3 khai th\u00e1c l\u1ed7 h\u1ed5ng trong th\u01b0 vi\u1ec7n v\u00e0 x\u00e1c th\u1ef1c nh\u01b0 m\u1ed9t ng\u01b0\u1eddi d\u00f9ng kh\u00e1c.<\/p>\n<p>\u201cTin t\u1eb7c sau \u0111\u00f3 l\u1ea5y t\u00e0i li\u1ec7u XML \u0111\u00e3 k\u00fd s\u1ed1 h\u1ee3p l\u1ec7 n\u00e0y v\u00e0 thao t\u00fang n\u00f3. Ch\u00fang ch\u00e8n m\u1ed9t SAML Assertion \u0111\u1ed9c h\u1ea1i th\u1ee9 hai v\u00e0o t\u00e0i li\u1ec7u. Assertion \u0111\u1ed9c h\u1ea1i n\u00e0y ch\u1ee9a danh t\u00ednh c\u1ee7a ng\u01b0\u1eddi d\u00f9ng m\u1ee5c ti\u00eau (v\u00ed d\u1ee5: t\u00ean ng\u01b0\u1eddi d\u00f9ng c\u1ee7a qu\u1ea3n tr\u1ecb vi\u00ean). K\u00fd s\u1ed1 h\u1ee3p l\u1ec7 t\u1eeb t\u00e0i li\u1ec7u g\u1ed1c v\u1eabn \u00e1p d\u1ee5ng cho c\u00e1c n\u1ed9i dung l\u00e0nh t\u00ednh trong XML, nh\u01b0ng c\u1ea5u tr\u00fac d\u1ec5 b\u1ecb t\u1ea5n c\u00f4ng c\u1ee7a SP s\u1ebd v\u00f4 t\u00ecnh x\u1eed l\u00fd x\u00e1c nh\u1eadn \u0111\u1ed9c h\u1ea1i, ch\u01b0a \u0111\u01b0\u1ee3c k\u00fd s\u1ed1\u201d, EndorLabs gi\u1ea3i th\u00edch.<\/p>\n<p>\u0110\u00e2y l\u00e0 c\u00e1ch b\u1ecf qua SSO ho\u00e0n to\u00e0n, cho ph\u00e9p k\u1ebb t\u1ea5n c\u00f4ng t\u1eeb xa tr\u00e1i ph\u00e9p th\u1ef1c hi\u1ec7n\u00a0<a href=\"https:\/\/antoanthongtin.vn\/tin\/lo-hong-nghiem-trong-trong-linux-kernel-cho-phep-ke-tan-cong-thuc-hien-leo-thang-dac-quyen\">leo thang \u0111\u1eb7c quy\u1ec1n<\/a>\u00a0v\u00e0 \u0111\u0103ng nh\u1eadp v\u1edbi t\u01b0 c\u00e1ch qu\u1ea3n tr\u1ecb vi\u00ean. K\u1ebb t\u1ea5n c\u00f4ng kh\u00f4ng c\u1ea7n t\u01b0\u01a1ng t\u00e1c v\u1edbi ng\u01b0\u1eddi d\u00f9ng ho\u1eb7c quy\u1ec1n h\u1ea1n \u0111\u1eb7c bi\u1ec7t, y\u00eau c\u1ea7u duy nh\u1ea5t l\u00e0 truy c\u1eadp v\u00e0o blob XML \u0111\u00e3 k\u00fd s\u1ed1 h\u1ee3p l\u1ec7, khi\u1ebfn vi\u1ec7c khai th\u00e1c tr\u1edf n\u00ean t\u01b0\u01a1ng \u0111\u1ed1i \u0111\u01a1n gi\u1ea3n.<\/p>\n<p>\u0110\u1ec3 gi\u1ea3m thi\u1ec3u r\u1ee7i ro, ng\u01b0\u1eddi d\u00f9ng \u0111\u01b0\u1ee3c khuy\u1ebfn ngh\u1ecb n\u00e2ng c\u1ea5p l\u00ean Samlify phi\u00ean b\u1ea3n 2.10.0, \u0111\u01b0\u1ee3c ph\u00e1t h\u00e0nh v\u00e0o \u0111\u1ea7u th\u00e1ng 5. Hi\u1ec7n t\u1ea1i, ch\u01b0a c\u00f3 b\u00e1o c\u00e1o n\u00e0o v\u1ec1 vi\u1ec7c khai th\u00e1c l\u1ed7 h\u1ed5ng CVE-2025-47949 trong th\u1ef1c t\u1ebf, nh\u01b0ng ng\u01b0\u1eddi d\u00f9ng b\u1ecb \u1ea3nh h\u01b0\u1edfng \u0111\u01b0\u1ee3c khuy\u1ebfn c\u00e1o n\u00ean h\u00e0nh \u0111\u1ed9ng ngay l\u1eadp t\u1ee9c v\u00e0 b\u1ea3o v\u1ec7 h\u1ec7 th\u1ed1ng c\u1ee7a m\u00ecnh.<\/p>\n<\/article>\n","protected":false},"excerpt":{"rendered":"<p>M\u1ed9t l\u1ed7 h\u1ed5ng x\u00e1c th\u1ef1c Samlify quan tr\u1ecdng \u0111\u00e3 \u0111\u01b0\u1ee3c c\u00e1c nh\u00e0 nghi\u00ean c\u1ee9u c\u1ee7a c\u00f4ng ty an ninh m\u1ea1ng EndorLabs (M\u1ef9) ph\u00e1t hi\u1ec7n, cho ph\u00e9p k\u1ebb t\u1ea5n c\u00f4ng m\u1ea1o danh ng\u01b0\u1eddi d\u00f9ng qu\u1ea3n tr\u1ecb b\u1eb1ng c\u00e1ch \u0111\u01b0a c\u00e1c x\u00e1c nh\u1eadn \u0111\u1ed9c h\u1ea1i v\u00e0o c\u00e1c response SAML \u0111\u00e3 \u0111\u01b0\u1ee3c k\u00fd s\u1ed1 h\u1ee3p l\u1ec7. Ph\u00e1t hi\u1ec7n [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":46214,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"tdm_status":"","tdm_grid_status":"","footnotes":""},"categories":[3,4,24,35],"tags":[],"class_list":["post-46213","post","type-post","status-publish","format-standard","has-post-thumbnail","category-canh-bao-khuyen-nghi","category-kien-thuc-an-toan-thong-tin","category-tin-noi-bat","category-tin-tuc-su-kien"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/posts\/46213","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/comments?post=46213"}],"version-history":[{"count":1,"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/posts\/46213\/revisions"}],"predecessor-version":[{"id":46215,"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/posts\/46213\/revisions\/46215"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/media\/46214"}],"wp:attachment":[{"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/media?parent=46213"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/categories?post=46213"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/tags?post=46213"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}