在 2020 年 3 月 23 日,William Bowling 在 hackerone 上发布了一份带有 PoC 的漏洞报告。
借助此漏洞,我们可以读取 GitLab 服务器上任何全局可读的文件(权限为 444 或更高),例如 /etc/passwd 等……(仅限全局可读文件)\
Notice that you should be authenticated user
我已在 GitLab 21.9.0 版本(Ubuntu 18.04)上进行了测试,但它与操作系统无关
非常感谢 exploit-db 团队发布此漏洞利用程序
https://www.exploit-db.com/exploits/48431
非常感谢 William Bowling
漏洞披露者:Biteable 公司的 William Bowling,又名 vakzz
https://hackerone.com/reports/827052