GitLab 7Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-07-02

0x00 ·ì϶¸ÅÊö

image.png

GitLabÊÇÒ»¸öÓÃÓÚ²Ö¿âÖÎÀíϵͳµÄ¿ªÔ´ÏîÄ¿£¬ £¬£¬£¬£¬£¬£¬ÆäʹÓÃGit×÷Ϊ´úÂëÖÎÀí¹¤¾ß£¬ £¬£¬£¬£¬£¬£¬¿Éͨ¹ýWeb½çÃæ½Ó¼û¹«¿ª»ò¸öÈËÏîÄ¿ ¡£¡£¡£¡£¡£¡£¡£¡£

2021Äê07ÔÂ01ÈÕ£¬ £¬£¬£¬£¬£¬£¬GitLab°ä²¼°²È«²¼¸æ£¬ £¬£¬£¬£¬£¬£¬½¨¸´ÁËGitLabÉçÇø°æ£¨CE£©ºÍÆóÒµ°æ£¨EE£©ÖеĶà¸ö°²È«·ì϶£¬ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶Ôì³ÉÐÅϢй¶¡¢»Ø¾ø·þÎñ¡¢Î´ÊÚȨ½Ó¼û»òÖ´ÐÐÆäËü²Ù×÷ ¡£¡£¡£¡£¡£¡£¡£¡£

 

0x01 ·ì϶ÏêÇé

±¾´Î½¨¸´µÄ·ìÏ¶Éæ¼°Dos¡¢CSRF¡¢ÐÅϢй¶¡¢Î´ÊÚȨ½Ó¼û¡¢XSSÒÔ¼°HTML×¢ÈëµÈ£¬ £¬£¬£¬£¬£¬£¬ÕâЩ·ì϶µÄCVSSv3ÆÀ·ÖÁìÓòΪ3.5-7.7 ¡£¡£¡£¡£¡£¡£¡£¡£

ÆäÖУ¬ £¬£¬£¬£¬£¬£¬¸ßΣ·ì϶Ϊ2¸ö£¨±ðÀëΪDosºÍCSRF£©£¬ £¬£¬£¬£¬£¬£¬ÖÐΣ·ì϶Ϊ15¸ö£¨Èç¸öÈËÏîÄ¿ÐÅϢй¶¡¢»Ø¾øÎªÓû§ÅäÖÃÎļþÒ³ÃæÌṩ·þÎñ¡¢Í£ÓõÄÓû§Äܹ»Í¨¹ýGraphQL½Ó¼ûÊý¾Ý£¬ £¬£¬£¬£¬£¬£¬ÒÔ¼°¸÷ÀàXSS·ì϶µÈ£©£¬ £¬£¬£¬£¬£¬£¬µÍΣ·ì϶Ϊ2¸ö£¨ÈçÈ«Ãû×Ö¶ÎÖеÄHTML×¢È룩 ¡£¡£¡£¡£¡£¡£¡£¡£

 

²¿ÃÅ·ì϶ÏêÇéÈçÏ£º

GitLab Webhook Dos·ì϶

GitLabµÄWebhookÖ°ÄÜÄܹ»±»ÀÄÓÃÀ´Ö´Ðлؾø·þÎñ¹¥»÷£¬ £¬£¬£¬£¬£¬£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.7 ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄÀûÓø´ÔӶȵ͡¢ËùÐèȨÏ޵ͣ¬ £¬£¬£¬£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥ ¡£¡£¡£¡£¡£¡£¡£¡£

 

GraphQL API CSRF·ì϶

GitLabµÄGraphQL API´æÔÚ¿çÕ¾ÒªÇóαÔì·ì϶£¬ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýGETÒªÇóÖ´Ðиü¸Ä²Ù×÷£¬ £¬£¬£¬£¬£¬£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.1 ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÎÞÐèÌØÊâȨÏÞ¼´¿ÉÀûÓ㬠£¬£¬£¬£¬£¬£¬²¢ÇÒÀûÓø´ÔӶȵͣ¬ £¬£¬£¬£¬£¬£¬µ«ÐèÓû§½»»¥ ¡£¡£¡£¡£¡£¡£¡£¡£

 

Ó°ÏìÁìÓò

Gitlab CE/EE < 14.0.2

Gitlab CE/EE < 13.12.6

Gitlab CE/EE < 13.11.6

 

0x02 ´ëÖý¨Òé

ĿǰÕâЩ·ì϶ÒѾ­½¨¸´£¬ £¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁÒÔϰ汾£º

Gitlab CE/EE  14.0.2

Gitlab CE/EE  13.12.6

Gitlab CE/EE  13.11.6

ÏÂÔØÁ´½Ó£º

https://about.gitlab.com/update/

 

0x03 ²Î¿¼Á´½Ó

https://about.gitlab.com/releases/2021/07/01/security-release-gitlab-14-0-2-released/

https://about.gitlab.com/update/

 

0x04 ¹¦·òÏß

2021-07-01    GitLab°ä²¼°²È«²¼¸æ

2021-07-02    VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png