Dangerous SSH commands: critical security hole in GitLab
Summary
In 2017 GitLab contained a critical hole (CVE-2017-12426) through which attackers could execute commands on the server when importing a repository by URL. An option flag injected into the URL caused the rest of the address to be interpreted as a command. Versions 7.9.0 to 9.4.3 were affected; Recurity Labs had previously found similar bugs in Git, Mercurial and other version control systems.
Ideas
- A URL that starts with a hyphen is read as an option by command line programs.
- On the server, the bug hits the whole installation, not just a single user.
- On the server, the Git command sometimes ran with far-reaching privileges.
- Fixes came for several supported version branches at the same time.
Insights
- Passing user input on to command line programs is a classic source of injection.
- Server services that fetch third-party repositories need the same care as clients, if anything more.
Facts
- The hole was fixed in 9.4.4, 9.3.10, 9.2.19, 9.1.10, 9.0.13 and 8.17.8.
- The developers rated the hole as critical.
References
Critique
- The report does not explain whether the import was possible for all users or only for logged-in accounts.
Recommendations
- Only pass user input to command line programs after a “--” marking the end of options.
- Keep self-hosted GitLab instances on a supported, current version branch.
Links to the original source and the Web Archive open in a new tab.