CVE-2020-10977 is an arbitrary file read vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 8.5 to 12.9. The vulnerability arises from a path traversal flaw when moving an issue between projects, allowing an attacker to read arbitrary files on the server by manipulating the file path during the issue move operation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (gitlab_file_read_rce.rb) that exploits a vulnerability in GitLab to achieve arbitrary file read and remote code execution. The exploit works by first authenticating to the GitLab instance using valid credentials, then abusing project and issue creation features to leak the application's secret_key_base from the secrets.yml file. With this secret, the module crafts a signed, serialized Ruby object as a cookie (experimentation_subject_id) to trigger deserialization and execute arbitrary code or read files. The module is operational and provides a full attack chain, including authentication, project/issue manipulation, secret extraction, and payload delivery. The main attack vector is network-based, targeting the GitLab web interface over HTTP(S). The code is well-structured, leverages Metasploit's HttpClient, and includes custom classes for message verification and key generation, mimicking Rails internals. The endpoints targeted are standard GitLab web and API paths. The exploit is not a detection script and is not fake; it is a real, functional exploit module.
This repository contains a Python exploit script (cve_2020_10977.py) and a detailed README for CVE-2020-10977, a path traversal vulnerability in GitLab versions 12.9.0 and below. The exploit allows an authenticated attacker to read arbitrary files from the server by abusing the way GitLab handles issue attachments and project moves. The script automates the process: it logs in to the target GitLab instance using provided credentials, creates two projects, crafts a malicious issue with a payload that references a file path via a path traversal sequence, and moves the issue to trigger the vulnerability. The attacker is prompted for an absolute file path, and the script retrieves and displays the file's contents. Cleanup is performed on exit by deleting the created projects. The exploit requires the attacker to have a valid user account on the target GitLab instance. The repository is well-structured, with clear usage instructions and dependency requirements (requests, bs4). No hardcoded endpoints are present; the target URL is supplied by the user at runtime. The main attack vector is network-based, targeting the web interface of GitLab.
This repository provides a working exploit for CVE-2020-10977, a vulnerability in GitLab CE 12.9.0 that allows an authenticated attacker to read arbitrary files and, by chaining this with Ruby deserialization, achieve remote code execution. The main script, 'get_secret.py', automates the process of logging into a target GitLab instance, exploiting the vulnerability to extract the 'secret_key_base' from the server's 'secrets.yml' file, and then uses 'cookie_maker.sh' to generate a malicious authentication cookie. This cookie, when sent to the vulnerable GitLab instance, executes an arbitrary shell command provided by the attacker. The exploit leverages Docker to run a local GitLab instance for crafting the payload. The repository includes a submodule with the original exploit code for the file read vulnerability, and provides detailed documentation on manual exploitation steps. The main attack vector is network-based, targeting a reachable GitLab instance. Key fingerprintable endpoints include the target URL, the secrets file path, and the temporary Ruby script used for payload generation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.