GitLab
Last updated
Last updated
http://gitlab.inlanefreight.local:8081/users/sign_in
The only way to footprint the GitLab version number in use is by browsing to the /help
page when logged in
Browse to /explore
and see if there are any public projects that may contain something interesting.
Check and see if we can register an account and access additional projects
http://gitlab.inlanefreight.local:8081/users/sign_up
GitLab's defaults are set to 10 failed attempts resulting in an automatic unlock after 10 minutes
GitLab Community Edition version 13.10.2 and lower suffered from an authenticated remote code execution
If we encounter a vulnerable version of GitLab that allows for self-registration, we can quickly sign up for an account and pull off the attack. Else, OSINT or password guessing
New Gitlab Accounts (created since the first affect version and if Gitlab is before the patched version) can be logged into with the following password:
123qweQWE!@#000000000
Source: https://x.com/HackerGautam/status/1520624546654867456
All the following GitLab (CE/EE) versions are vulnerable:
< 16.11.10
17.0.0 < 17.0.8
17.0.0 < 17.1.8
17.0.0 < 17.2.7
17.0.0 < 17.3.3