Access Projects And create projects in gitlab pre production server

Disclosed: 2019-08-28 17:49:17 By uzsunnyz To gitlab
Low
Vulnerability Details
### Steps to reproduce Go to https://pre.gitlab.com Here any one can register and can view the pre production projects of gitlab developers. I have registered in https://pre.gitlab.com/users/sign_in and have created one test group and test project go to https://pre.gitlab.com/explore/groups i have created one test group {F470509} And i have created one test project {F470510} I went to look for gitlab project members https://pre.gitlab.com/qa-perf-testing/gitlabhq/project_members I have seen it was created by your gitlab employee Ramya Authappan https://pre.gitlab.com/rauthappan The attacker not only access the internal projects of gitlab but he can also create groups and projects in pre production server of gitlab. ## Impact Attacker will access the pre production server of gitlab and he access the groups and projects created by gitlab employees. Attacker will also create the projects and groups in pre production server of gitlab.
Actions
View on HackerOne
Report Stats
  • Report ID: 540711
  • State: Closed
  • Substate: resolved
  • Upvotes: 27
Share this report