gitlab-public-snippets: GitLab public snippets

日期: 2025-09-01 | 影响软件: GitLab | POC: 已公开

漏洞描述

2023/11/29 change info to high of severity level.

PoC代码[已公开]

id: gitlab-public-snippets

info:
  name: GitLab public snippets
  author: pdteam
  severity: high
  description: |-
    2023/11/29 change info to high of severity level.
  reference:
    - https://gist.github.com/vysecurity/20311c29d879e0aba9dcffbe72a88b10
    - https://twitter.com/intigriti/status/1375078783338876929
  tags: gitlab
  created: 2023/11/29

rules:
  r0:
    request:
      method: GET
      path: /explore/snippets
    expression: response.status == 200 && (response.body.ibcontains(b'<title>Snippets · Explore · GitLab</title>') || response.body.bcontains(b'No snippets found')  || response.body.bcontains(b'No snippets found'))
  r1:
    request:
      method: GET
      path: /-/snippets
      follow_redirects: true
    expression: response.status == 200 && (response.body.ibcontains(b'<title>Snippets · Explore · GitLab</title>') || response.body.bcontains(b'No snippets found')  || response.body.bcontains(b'No snippets found'))
expression: r0() || r1()

相关漏洞推荐