GitLab 7Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2021-07-02

0x00 ©¶´¸ÅÊö

image.png

GitLabÊÇÒ»¸öÓÃÓÚ¶ÑÕ»¹ÜÀíϵͳµÄ¿ªÔ´ÏîÄ¿£¬ÆäʹÓÃGit×÷Ϊ´úÂë¹ÜÀí¹¤¾ß£¬¿Éͨ¹ýWeb½çÃæ·ÃÎʹûÈ»»ò˽ÈËÏîÄ¿¡£

2021Äê07ÔÂ01ÈÕ£¬GitLabÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËGitLabÉçÇø°æ£¨CE£©ºÍÆóÒµ°æ£¨EE£©ÖеĶà¸öÄþ¾²Â©¶´£¬¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ©¶´Ôì³ÉÐÅϢй¶¡¢¾Ü¾ø·þÎñ¡¢Î´ÊÚȨ·ÃÎÊ»òÖ´ÐÐÆäËü²Ù×÷¡£

 

0x01 ©¶´ÏêÇé

±¾´ÎÐÞ¸´µÄ©¶´Éæ¼°Dos¡¢CSRF¡¢ÐÅϢй¶¡¢Î´ÊÚȨ·ÃÎÊ¡¢XSSÒÔ¼°HTML×¢ÈëµÈ£¬ÕâЩ©¶´µÄCVSSv3ÆÀ·Ö·¶Î§Îª3.5-7.7¡£

ÆäÖУ¬¸ßΣ©¶´Îª2¸ö£¨·Ö±ðΪDosºÍCSRF£©£¬ÖÐΣ©¶´Îª15¸ö£¨Èç˽ÈËÏîÄ¿ÐÅϢй¶¡¢¾Ü¾øÎªÓû§ÅäÖÃÎļþÒ³ÃæÌṩ·þÎñ¡¢Í£ÓõÄÓû§¿ÉÒÔͨ¹ýGraphQL·ÃÎÊÊý¾Ý£¬ÒÔ¼°ÖÖÖÖXSS©¶´µÈ£©£¬µÍΣ©¶´Îª2¸ö£¨ÈçÈ«Ãû×Ö¶ÎÖеÄHTML×¢È룩¡£

 

²¿ÃÅ©¶´ÏêÇéÈçÏ£º

GitLab Webhook Dos©¶´

GitLabµÄWebhook¹¦Ð§¿ÉÒÔ±»ÀÄÓÃÀ´Ö´Ðоܾø·þÎñ¹¥»÷£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.7¡£¸Ã©¶´µÄÀûÓÃÅÓ´ó¶ÈµÍ¡¢ËùÐèȨÏ޵ͣ¬ÇÒÎÞÐèÓû§½»»¥¡£

 

GraphQL API CSRF©¶´

GitLabµÄGraphQL API´æÔÚ¿çÕ¾ÇëÇóαÔì©¶´£¬¹¥»÷Õß¿ÉÒÔͨ¹ýGETÇëÇóÖ´Ðиü¸Ä²Ù×÷£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.1¡£¸Ã©¶´ÎÞÐèÌØÊâȨÏÞ¼´¿ÉÀûÓ㬶øÇÒÀûÓÃÅÓ´ó¶ÈµÍ£¬µ«ÐèÓû§½»»¥¡£

 

Ó°Ï췶Χ

Gitlab CE/EE < 14.0.2

Gitlab CE/EE < 13.12.6

Gitlab CE/EE < 13.11.6

 

0x02 ´¦Öý¨Òé

ĿǰÕâЩ©¶´ÒѾ­ÐÞ¸´£¬½¨ÒéÉý¼¶ÖÁÒÔϰ汾£º

Gitlab CE/EE  14.0.2

Gitlab CE/EE  13.12.6

Gitlab CE/EE  13.11.6

ÏÂÔØÁ´½Ó£º

https://about.gitlab.com/update/

 

0x03 ²Î¿¼Á´½Ó

https://about.gitlab.com/releases/2021/07/01/security-release-gitlab-14-0-2-released/

https://about.gitlab.com/update/

 

0x04 ʱ¼äÏß

2021-07-01    GitLabÐû²¼Äþ¾²Í¨¸æ

2021-07-02    VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png