Gitlab Project Import Remote Code Execution

Strike ID:
E23-1fjd1
CVSS:
9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
False Positive:
f
Variants:
2
Year:
2022

Description

This strike exploits an OS command injection vulnerability in Gitlab. The vulnerability is due to improper handling of the import_source field. A remote Authenticated attacker can exploit the vulnerability by performing a bulk import from a server controlled by the attacker. Successful exploitation can result in remote code execution. Note: This strike includes just the last part of the attack where targeted server requires data from the custom server controlled by the attacker and the attacker's response.

CVE

References