GitLab 7Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-07-02

0x00 Îó²î¸ÅÊö

image.png

GitLabÊÇÒ»¸öÓÃÓÚ¿ÍÕ»¹ÜÀíϵͳµÄ¿ªÔ´ÏîÄ¿£¬ÆäʹÓÃGit×÷Ϊ´úÂë¹ÜÀí¹¤¾ß£¬¿Éͨ¹ýWeb½çÃæ»á¼û¹ûÕæ»ò˽ÈËÏîÄ¿¡£

2021Äê07ÔÂ01ÈÕ£¬GitLabÐû²¼Ç徲ͨ¸æ£¬ÐÞ¸´ÁËGitLabÉçÇø°æ£¨CE£©ºÍÆóÒµ°æ£¨EE£©ÖеĶà¸öÇå¾²Îó²î£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÔì³ÉÐÅϢй¶¡¢¾Ü¾ø·þÎñ¡¢Î´ÊÚȨ»á¼û»òÖ´ÐÐÆäËü²Ù×÷¡£

 

0x01 Îó²îÏêÇé

±¾´ÎÐÞ¸´µÄÎó²îÉæ¼°Dos¡¢CSRF¡¢ÐÅϢй¶¡¢Î´ÊÚȨ»á¼û¡¢XSSÒÔ¼°HTML×¢ÈëµÈ£¬ÕâЩÎó²îµÄCVSSv3ÆÀ·Ö¹æÄ£Îª3.5-7.7¡£

ÆäÖУ¬¸ßΣÎó²îΪ2¸ö£¨»®·ÖΪDosºÍCSRF£©£¬ÖÐΣÎó²îΪ15¸ö£¨Èç˽ÈËÏîÄ¿ÐÅϢй¶¡¢¾Ü¾øÎªÓû§ÉèÖÃÎļþÒ³ÃæÌṩ·þÎñ¡¢Í£ÓõÄÓû§¿ÉÒÔͨ¹ýGraphQL»á¼ûÊý¾Ý£¬ÒÔ¼°ÖÖÖÖXSSÎó²îµÈ£©£¬µÍΣÎó²îΪ2¸ö£¨ÈçÈ«Ãû×Ö¶ÎÖеÄHTML×¢È룩¡£

 

²¿·ÖÎó²îÏêÇéÈçÏ£º

GitLab Webhook DosÎó²î

GitLabµÄWebhook¹¦Ð§¿ÉÒÔ±»ÀÄÓÃÀ´Ö´Ðоܾø·þÎñ¹¥»÷£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.7¡£¸ÃÎó²îµÄʹÓÃÖØÆ¯ºóµÍ¡¢ËùÐèȨÏ޵ͣ¬ÇÒÎÞÐèÓû§½»»¥¡£

 

GraphQL API CSRFÎó²î

GitLabµÄGraphQL API±£´æ¿çÕ¾ÇëÇóαÔìÎó²î£¬¹¥»÷Õß¿ÉÒÔͨ¹ýGETÇëÇóÖ´Ðиü¸Ä²Ù×÷£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.1¡£¸ÃÎó²îÎÞÐèÌØÊâȨÏÞ¼´¿ÉʹÓ㬲¢ÇÒʹÓÃÖØÆ¯ºóµÍ£¬µ«ÐèÓû§½»»¥¡£

 

Ó°Ïì¹æÄ£

Gitlab CE/EE < 14.0.2

Gitlab CE/EE < 13.12.6

Gitlab CE/EE < 13.11.6

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÕâЩÎó²îÒѾ­ÐÞ¸´£¬½¨ÒéÉý¼¶ÖÁÒÔϰ汾£º

Gitlab CE/EE  14.0.2

Gitlab CE/EE  13.12.6

Gitlab CE/EE  13.11.6

ÏÂÔØÁ´½Ó£º

https://about.gitlab.com/update/

 

0x03 ²Î¿¼Á´½Ó

https://about.gitlab.com/releases/2021/07/01/security-release-gitlab-14-0-2-released/

https://about.gitlab.com/update/

 

0x04 ʱ¼äÏß

2021-07-01    GitLabÐû²¼Ç徲ͨ¸æ

2021-07-02    VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png