$12,000 Grafana SSRF in Gitlab - Bug Bounty Reports Explained

Опубликовано: 31 Октябрь 2024
на канале: Bug Bounty Reports Explained
7,696
334

📧 Subscribe to BBRE Premium: https://bbre.dev/premium
✉️ Sign up for the mailing list: https://bbre.dev/nl
📣 Follow me on Twitter: https://bbre.dev/tw


This video is about Grafana SSRF vulnerability that was reported to Gitlab bug bounty program on Hackerone. The reward for this bug was $12,000, as it was possible to request AWS metadata endpoint.

Follow me on twitter:
  / gregxsunday  

Report:
https://hackerone.com/reports/878779

Justin Gardner:
  / rhynorater  

His talk on this topic - speaks about more ways of exploitation:
writeup:
https://rhynorater.github.io/CVE-2020...
video:
   • h@cktivitycon 2020: Graphing Out Inte...  
slides: https://docs.google.com/presentation/...

Fragments of vulnerable Grafana source code:
https://github.com/grafana/grafana/bl...
https://github.com/grafana/grafana/bl...

Timestamps:
00:00 Intro
00:24 Redirect chain
03:56 Payload
04:24 Outro

#grafana #ssrf #gitlab #bug #bounty