** Descrizione
- POC per CVE-2021-22205: Gitlab CE/EE RCE Vulnerabilità di esecuzione remota di codice non autorizzata POC && EXP
- creato da antx il 2021-10-29.
** Dettaglio
- È stato scoperto un problema in GitLab CE/EE che interessa tutte le versioni a partire dalla 11.9. GitLab non convalidava correttamente i file immagine passati a un parser di file, il che ha portato all'esecuzione remota di comandi.
** Gravità CVE
- attackComplexity: LOW
- attackVector: NETWORK
- availabilityImpact: HIGH
- confidentialityImpact: HIGH
- integrityImpact: HIGH
- privilegesRequired: NONE
- scope: CHANGED
- userInteraction: NONE
- version: 3.1
- baseScore: 10
- baseSeverity: CRITICAL
** Versioni affette
- Gitlab CE/EE < 13.10.3
- Gitlab CE/EE < 13.9.6
- Gitlab CE/EE < 13.8.8
** POC
- [[./CVE-2021-22205.py][Python-Poc]]
** Riferimenti
- POC
- [[https://github.com/mr-r3bot/Gitlab-CVE-2021-22205][mr-r3bot/Gitlab-CVE-2021-22205]]
- [[https://github.com/RedTeamWing/CVE-2021-22205][RedTeamWing/CVE-2021-22205]]
- [[https://github.com/r0eXpeR/CVE-2021-22205][r0eXpeR/CVE-2021-22205]]
- Articolo
- [[https://about.gitlab.com/releases/2021/04/14/security-release-gitlab-13-10-3-released/][Gitlab-Security-Release]]
- [[https://www.freebuf.com/news/303441.html][高危漏洞曝光半年之久,超一半的GitLab 服务器仍未修复]]
- CVE
- [[https://github.com/CVEProject/cvelist/blob/master/2021/22xxx/CVE-2021-22205.json][CVE-2021-22205]]