bk99.de entertain the web since 1997

Dangerous SSH commands: critical security hole in GitLab

Summary

In 2017 GitLab contained a critical hole (CVE-2017-12426) through which attackers could execute commands on the server when importing a repository by URL. An option flag injected into the URL caused the rest of the address to be interpreted as a command. Versions 7.9.0 to 9.4.3 were affected; Recurity Labs had previously found similar bugs in Git, Mercurial and other version control systems.

Ideas

  • A URL that starts with a hyphen is read as an option by command line programs.
  • On the server, the bug hits the whole installation, not just a single user.
  • On the server, the Git command sometimes ran with far-reaching privileges.
  • Fixes came for several supported version branches at the same time.

Insights

  • Passing user input on to command line programs is a classic source of injection.
  • Server services that fetch third-party repositories need the same care as clients, if anything more.

Facts

  • The hole was fixed in 9.4.4, 9.3.10, 9.2.19, 9.1.10, 9.0.13 and 8.17.8.
  • The developers rated the hole as critical.

References

Critique

  • The report does not explain whether the import was possible for all users or only for logged-in accounts.

Recommendations

  • Only pass user input to command line programs after a “--” marking the end of options.
  • Keep self-hosted GitLab instances on a supported, current version branch.

Read the original article

Search the Web Archive