
CVE-2020-13277 靶场: Gitlab 逻辑漏洞 - 任意用户越权访问私有仓库
CVE-2020-13277 Lab: GitLab Logic Vulnerability - Unauthorized User Access to Private Repositories
CVE-2020-13277
├── README.md ............... [This README file]
├── imgs .................... [Images for README]
├── gitlab .................. [Gitlab container mount directory]
│ ├── Dockerfile .......... [Docker build file for Gitlab]
│ ├── config .............. [Gitlab config mount directory]
│ ├── data ................ [Gitlab data mount directory]
│ ├── logs ................ [Gitlab logs mount directory]
│ ├── keys ................ [Gitlab cracked license storage directory]
│ └── runner .............. [Runner container mount directory]
├── license ................. [Container build directory for cracked license]
│ ├── Dockerfile .......... [Docker build file for License]
│ └── license.rb .......... [Ruby script to generate cracked license]
├── docker-compose.yml ...... [Docker build configuration]
├── keygen.ps1 .............. [Windows: one-click generate cracked license]
├── keygen.sh ............... [Linux: one-click generate cracked license]
├── run.ps1 ................. [Windows: one-click run Gitlab lab]
├── run.sh .................. [Linux: one-click run Gitlab lab]
├── register.ps1 ............ [Windows: one-click register Runner]
├── register.sh ............. [Linux: one-click register Runner]
├── stop.ps1 ................ [Windows: one-click stop Gitlab lab]
└── stop.sh ................. [Linux: one-click stop Gitlab lab]
The core of this vulnerability primarily exploits Mirror Repository - the mirror synchronization backup function of repositories.
Mirror synchronization has two directions:
This vulnerability exploits the Pull direction of Mirror Repository.
It is known that GitLab is divided into two versions: CE (Community Free Edition) and EE (Enterprise Paid Edition), and GitLab officially states that this vulnerability affects the following versions of both CE and EE:
>=10.6, <12.9.10>=12.10, <12.10.11>=13.0, <13.0.6However, this does not mean that all these versions of Gitlab Docker Image can be used to build the lab, because:
In other words, to build the lab using Docker, you must choose the Gitlab-EE version and crack it (or purchase a License if you are rich) to activate the Mirror Repository - Pull function.
But even after cracking Gitlab-EE, whether it is 10.x, 12.x, or 13.x, when the Mirror Repository - Pull URL contains a local path, it will report an error Import url is blocked: Requests to localhost are not allowed.
Although you can configure a local URL by setting Allow requests to the local network from hooks and services via Admin area => Settings => Network => Outbound requests, synchronizing the mirror will report an error 2:Fetching remote upstream failed: fatal: unable to access http://127.0.0.1/xxxx/: The requested URL returned error: 301. In other words, only Pull Remote Repository is available.
Fortunately, although 12.x and 13.x are very strict in judging local URLs, the 10.x version has a workaround: when configuring the Pull URL, simply use a locally configured DNS service name to bypass.
In summary, the final choice is to use the gitlab-ee:10.6.0-ee.0 version of the Docker Image to build this lab.
In fact, from the above description, it can be seen that the exploitation conditions for this vulnerability are quite strict, and basically poor people are unlikely to be affected by this vulnerability.
./keygen.sh or ./keygen.ps1./run.sh or ./run.ps1When generating the cracked key pair earlier, the public key has already been written into the GitLab container backend. The private key still needs to be uploaded to GitLab through the frontend to complete the cracking:
./gitlab/keys/ directory, copy the content of .gitlab-license (the private key) from itEnter license key, paste the private key, and click the Upload license button to complete the crackingAt this point, the Mirror Repository - Pull function is activated

Outbound requests at the very bottom and check Allow requests to the local network from hooks and services, then saveNow Mirror Repository - Pull supports pulling local Repository

./register.sh $TOKEN or ./register.ps1 $TOKENNow all Repository can use this Runner to execute CI scripts (Pipeline Jobs)

The verification process can refer to the official Issue, but the following verification process will be slightly adjusted for this lab.