Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2024-5655 PoC — Improper Access Control in GitLab

Source
Associated Vulnerability
Title:Improper Access Control in GitLab (CVE-2024-5655)
Description:An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.
Description
Private exploit CVE-2024-5655 to Gitlab (Private repositories disclosure)
Readme
# CVE-2024-5655-Gitlab-CSRF-GraphQL
Private exploit CVE-2024-5655 to Gitlab (Private repositories disclosure)

> The repository provides a working variant of the CVE-2024-5655 vulnerability exploit with support for real-time active shell, multithreading, entering targets from a file, and color output.

## 🔥 **CVSS: 9.6/10**

## Description
CVE-2024-5655 is a critical vulnerability in GitLab that allows attackers to execute CI/CD pipelines as any user, under specific conditions. This issue affects various versions of GitLab and has been addressed in the latest updates.

## Exploit details
The vulnerability enables unauthorized execution of CI/CD pipelines, potentially leading to remote code execution and other malicious activities.

## Running instructions
To run the exploit, use the following command:

```bash
python3 cve-2024-5655.py -t https://gitlab-private-repo -c 'cat README.md'
```
Before running the exploit, please refer to the README.txt file in the repository for detailed instructions.

## Vulnerable versions:
Various versions of GitLab before the latest security patch.

## Download
[Download here](https://t.ly/chSw3) (securely!)

## Date of published: 03.07.2024

## Contact
vulnresearcher@exploit.in

File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →