logo

Auditing GitLab: Public Gitlab Projects on Internal Networks

ID: 38825220-2cc9-544a-8bd6-5ac16bb510ee

STIX ID: report--38825220-2cc9-544a-8bd6-5ac16bb510ee

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2024-07-18

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog post demonstrates an unauthenticated technique to enumerate public projects on self-hosted GitLab instances via the projects API, mass-clone repositories, run secret-scanning tools (Gitleaks) on the repos, and aggregate findings into a single CSV; it includes proof-of-concept Python and Go scripts, workflow examples (Nuclei), and remediation/mitigation guidance to prevent leakage of credentials and tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.