GitLab gitlab-shell Repository Import Feature 远程代码执行漏洞

2014-05-13 GitLab PoC No

Description

GitLab是一套利用Ruby on Rails开发的一套开源的可实现自托管的Git(版本控制系统)项目仓库的应用程序。gitlab-shell是其中的一套用于SSH访问和存储库管理的应用程序。 GitLab中使用的gitlab-shell 1.7.4之前版本的repository import功能中存在安全漏洞。远程攻击者可通过导入URL利用该漏洞执行任意命令。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

References

Related Vulnerabilities