Skip to content

GitLab

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
W
WebComplete_Skeleton
  • Project overview
    • Project overview
    • Details
    • Activity
    • Releases
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 0
    • Issues 0
    • List
    • Boards
    • Labels
    • Service Desk
    • Milestones
  • Jira
    • Jira
  • Merge Requests 1
    • Merge Requests 1
  • CI / CD
    • CI / CD
    • Pipelines
    • Jobs
    • Schedules
  • Operations
    • Operations
    • Incidents
    • Environments
  • Analytics
    • Analytics
    • CI / CD
    • Repository
    • Value Stream
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar

Hi Sir, mv-data.at Team Introduce, I'm Alexander. I work as Bug Bounty Hunter. I found a vulnerability in an existing Gitlab system Gitlab RCE which allows me to change the gitlab administrator/root password (Takeover admin gitlab login) and also be able to view all source code and secret credentials make reverse shell to the operation system. This finding is Critical Vulnerability. Impact:

Attacker can delete and download the source code and obtain various credentials. (database[SQL Command], API, credential : username & password) Attacker can embed ransomware and demand a ransom for all your data Can distribute the existing code in gitlab or sell it causing damage to the reputation Can exploit the gitlab and all source code of your data dev or master RCE Access can delete and manage your files or data. Email: alexandergiat@gmail.com
  • Public
  • WebComplete_Skeleton
  • Merge Requests
  • !1

Open
Opened Sep 21, 2018 by Vojislav Vukovic@Vojislav
  • Report abuse
Report abuse

#1 BASIC THINGS - Added basic UI elements for ADMIN Mode

  • Overview 1
  • Commits 51
  • Pipelines 1
  • Changes 115
  • Navigation component created in project with all buttons and information's;
  • Navigation bar is responsive across all devices and screen sizes;

For modal popups work is in progress

Assignee
Assign to
Reviewer
Request review from
None
Milestone
None
Assign milestone
Time tracking
Reference: p/WebComplete_Skeleton!1
Source branch: dev