How to reproduce the GitLab arbitrary file read vulnerability CVE-2020-10977
This article introduces GitLab arbitrary file read vulnerability CVE-2020-10977 how to reproduce, the content is very detailed, interested friends can refer to, hope to be helpful to you.
Introduction to 0x00
GitLab is an open source project for warehouse management system, which uses Git as a code management tool and builds web services on this basis. GitLab is developed by GitLabInc. Develop a web-based Git warehouse management tool using a MIT license with wiki and issue tracking capabilities. Use Git as a code management tool, and build a web service on this basis.
Overview of 0x01 vulnerabilities
In Gitlab version 8.5-12.9, there is an arbitrary file read vulnerability that can be exploited by attackers to read arbitrary files without privileges, resulting in serious information disclosure and the risk of further attack.
0x02 affects version
GitLab GitLab CE/EE > = 8.5 and = 8.5