Executive brief
gitlabhook is a Node.js package that integrates GitLab webhooks with local system commands. The package fails to sanitize incoming webhook data and directly passes it to system command execution, allowing an attacker to inject arbitrary commands. An attacker with network access to the webhook endpoint can execute arbitrary code on the server, leading to complete system compromise.
Technical details
This vulnerability is a classic command injection flaw (CWE-78) in the gitlabhook npm package. The vulnerability exists because the package concatenates user-supplied input from POST request bodies directly into exec() calls without validation or sanitization. Attack vector is network-based with no authentication required (any network-reachable instance is exploitable). An unauthenticated attacker can send a specially-crafted POST request to the webhook endpoint with shell metacharacters in the payload, causing arbitrary commands to execute with the privileges of the process running gitlabhook. All versions through 0.0.17 are vulnerable, and no fix has been released; users are advised to migrate to alternative packages.
Affected products
- npm gitlabhook 0 through 0.0.17
Timeline
- 2019-09-13: disclosed: NVD publication
- 2019-09-16: advisory: GHSA advisory published