GitLab 4ÔÂí§ÒâÎļþ¶ÁÈ¡Îó²î
Ðû²¼Ê±¼ä 2021-04-010x00 Îó²î¸ÅÊö
CVE ID | ʱ ¼ä | 2021-04-01 | |
Àà ÐÍ | í§ÒâÎļþ¶ÁÈ¡ | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà |
0x01 Îó²îÏêÇé

GitLab ÊÇÒ»¸öÓÃÓÚ¿ÍÕ»ÖÎÀíϵͳµÄ¿ªÔ´ÏîÄ¿£¬£¬£¬£¬£¬£¬£¬ÆäʹÓÃGit×÷Ϊ´úÂëÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ýWeb½çÃæ»á¼û¹ûÕæ»ò˽ÈËÏîÄ¿¡£¡£¡£¡£¡£¡£¡£
2021Äê03ÔÂ31ÈÕ£¬£¬£¬£¬£¬£¬£¬GitlabÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬¹ûÕæÁËGitLabÉçÇø°æ£¨CE£©ºÍÆóÒµ°æ£¨EE£©ÖеĶà¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇÒ»¸öí§ÒâÎļþ¶ÁÈ¡Îó²î£¬£¬£¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ9.6£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýµ¼ÈëÌØ¶¨ÎļþÀ´¶ÁȡЧÀÍÆ÷ÉϵÄí§ÒâÎļþ£»£»£»£»£»ÒÔ¼°Ò»¸öKrokií§ÒâÎļþ¶ÁÈ¡Îó²î£¬£¬£¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ7.5£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÌØÖÆµÄWikiÒ³ÃæÀ´¶ÁȡЧÀÍÆ÷ÉϵÄí§ÒâÎļþ¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
Gitlab CE/EE < 13.8.7
Gitlab CE/EE < 13.9.5
Gitlab CE/EE < 13.10.1
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ¹Ù·½ÒÑÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁÒÔϰ汾£º
Gitlab CE/EE 13.8.7
Gitlab CE/EE 13.9.5
Gitlab CE/EE 13.10.1
ÏÂÔØÁ´½Ó£º
https://about.gitlab.com/update/
0x03 ²Î¿¼Á´½Ó
https://about.gitlab.com/releases/2021/03/31/security-release-gitlab-13-10-1-released/
https://about.gitlab.com/update/
0x04 ʱ¼äÏß
2021-03-31 GitLabÐû²¼Ç徲ͨ¸æ
2021-04-01 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ