Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2020-13277 — CVE-2020-13277 靶场: Gitlab 逻辑漏洞 - 任意用户越权访问私有仓库 | Kitploit
Tools/GitHubGitHub/exp-docs/cve-2020-13277
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationLabs & Practice
GitHubexp-docs/cve-2020-13277

CVE-2020-13277

CVE-2020-13277 靶场: Gitlab 逻辑漏洞 - 任意用户越权访问私有仓库

View Repository
283123 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2020-13277

CVE-2020-13277 Lab: GitLab Logic Vulnerability - Unauthorized User Access to Private Repositories


0x10 Lab Environment

0x20 Directory Structure

CVE-2020-13277
├── README.md ............... [This README file]
├── imgs .................... [Images for README]
├── gitlab .................. [Gitlab container mount directory]
│   ├── Dockerfile .......... [Docker build file for Gitlab]
│   ├── config .............. [Gitlab config mount directory]
│   ├── data ................ [Gitlab data mount directory]
│   ├── logs ................ [Gitlab logs mount directory]
│   ├── keys ................ [Gitlab cracked license storage directory]
│   └── runner .............. [Runner container mount directory]
├── license ................. [Container build directory for cracked license]
│   ├── Dockerfile .......... [Docker build file for License]
│   └── license.rb .......... [Ruby script to generate cracked license]
├── docker-compose.yml ...... [Docker build configuration]
├── keygen.ps1 .............. [Windows: one-click generate cracked license]
├── keygen.sh ............... [Linux:   one-click generate cracked license]
├── run.ps1 ................. [Windows: one-click run Gitlab lab]
├── run.sh .................. [Linux:   one-click run Gitlab lab]
├── register.ps1 ............ [Windows: one-click register Runner]
├── register.sh ............. [Linux:   one-click register Runner]
├── stop.ps1 ................ [Windows: one-click stop Gitlab lab]
└── stop.sh ................. [Linux:   one-click stop Gitlab lab]

0x30 Preliminary Notes

About the Basis for Choosing the Lab Docker Image Version

The core of this vulnerability primarily exploits Mirror Repository - the mirror synchronization backup function of repositories.

Mirror synchronization has two directions:

  • Pull: Pulls the content of a specified Repository into the current Repository
  • Push: Pushes the content of the current Repository to a specified Repository

This vulnerability exploits the Pull direction of Mirror Repository.

It is known that GitLab is divided into two versions: CE (Community Free Edition) and EE (Enterprise Paid Edition), and GitLab officially states that this vulnerability affects the following versions of both CE and EE:

  • >=10.6, <12.9.10
  • >=12.10, <12.10.11
  • >=13.0, <13.0.6

However, this does not mean that all these versions of Gitlab Docker Image can be used to build the lab, because:

  • The CE version of Mirror Repository only has the Push direction
  • The EE version is further divided into Core, Starter, Premium, and Ultimate. From the official feature comparison table, it is known that only the Core version lacks the Pull direction, and all Gitlab-EE Docker Images provide only the Core version

In other words, to build the lab using Docker, you must choose the Gitlab-EE version and crack it (or purchase a License if you are rich) to activate the Mirror Repository - Pull function.

But even after cracking Gitlab-EE, whether it is 10.x, 12.x, or 13.x, when the Mirror Repository - Pull URL contains a local path, it will report an error Import url is blocked: Requests to localhost are not allowed.

Although you can configure a local URL by setting Allow requests to the local network from hooks and services via Admin area => Settings => Network => Outbound requests, synchronizing the mirror will report an error 2:Fetching remote upstream failed: fatal: unable to access http://127.0.0.1/xxxx/: The requested URL returned error: 301. In other words, only Pull Remote Repository is available.

Fortunately, although 12.x and 13.x are very strict in judging local URLs, the 10.x version has a workaround: when configuring the Pull URL, simply use a locally configured DNS service name to bypass.

In summary, the final choice is to use the gitlab-ee:10.6.0-ee.0 version of the Docker Image to build this lab.

In fact, from the above description, it can be seen that the exploitation conditions for this vulnerability are quite strict, and basically poor people are unlikely to be affected by this vulnerability.

0x40 Lab Setup

0x41 Build

  • The host machine must have Docker and Docker Compose pre-installed
  • Download this repository: git clone https://github.com/lyy289065406/CVE-2020-13277
  • Generate cracked key pair: ./keygen.sh or ./keygen.ps1
  • Build and run GitLab (ensure port 80 is not occupied): ./run.sh or ./run.ps1
  • After about 5 minutes, you can log in to GitLab from the browser: http://127.0.0.1 (the first login requires resetting the password of the admin account root)

0x42 Crack

When generating the cracked key pair earlier, the public key has already been written into the GitLab container backend. The private key still needs to be uploaded to GitLab through the frontend to complete the cracking:

  • The key pair is generated in the ./gitlab/keys/ directory, copy the content of .gitlab-license (the private key) from it
  • Open http://127.0.0.1/admin/license/new as the root user
  • Choose Enter license key, paste the private key, and click the Upload license button to complete the cracking

At this point, the Mirror Repository - Pull function is activated

0x43 Outbound Settings

  • Open http://127.0.0.1/admin/application_settings as the root user
  • Find Outbound requests at the very bottom and check Allow requests to the local network from hooks and services, then save

Now Mirror Repository - Pull supports pulling local Repository

0x44 Setup Runner

  • Open http://127.0.0.1/admin/runners as the root user
  • Find the registration token and copy it
  • Register the Runner: ./register.sh $TOKEN or ./register.ps1 $TOKEN

Now all Repository can use this Runner to execute CI scripts (Pipeline Jobs)

0x50 Lab Verification

The verification process can refer to the official Issue, but the following verification process will be slightly adjusted for this lab.

0x51 Pre-build Accounts for Verification

Download Tool