漏洞描述 GitLab是由GitLabInc.开发,使用MIT许可证的基于网络的Git仓库管理工具,具有issue跟踪功能。它使用Git作为代码管理工具,并在此基础上搭建起来的web服务。当启用对内部网络的webhooks 请求时,GitLab CE/EE 中的服务器端请求伪造漏洞影响从 10.5 开始的所有版本,即使在注册受限的 GitLab实例上也可能被未经身份验证的攻击者利用。
相关漏洞推荐 CVE-2020-26413: GitLab Information Disclosure POC 2025-09-01 | GitLab fofa app="GitLab" CVE-2021-22205: GitLab CE/EE Unauthenticated RCE Using ExifTool POC 2025-09-01 | GitLab CE EE An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was n... gitlab-weak-login: Gitlab Default Login POC 2025-09-01 | Gitlab Gitlab default login credentials were discovered. ShowDoc /server/index.php?s=/api/adminUpdate/download 文件上传漏洞(CVE-2021-36440) 无POC 2025-09-12 | ShowDoc ShowDoc 2.9.5版本存在一个高危的文件上传漏洞(CVE-2021-36440),该漏洞源于系统未能对上传文件的类型进行充分验证。攻击者可以绕过安全限制上传任意类型的危险文件,包括但不限于PH... CVE-2021-1497: Cisco HyperFlex HX Data Platform - Remote Command Execution POC 2025-09-01 | Cisco HyperFlex HX Data Platform Cisco HyperFlex HX contains multiple vulnerabilities in the web-based management interface that coul...