Detailed guide

1. Add XEIZE_TOKEN

Add XEIZE_TOKEN and XEIZE_GITLAB_API_TOKEN as CI/CD variables for GitLab Workflow.

Open Settings > CI/CD to add the variables.

GitLab PAT token scope:

  • api
GitLab CI/CD variable settings
Adding a GitLab CI/CD variable

2. Add the GitLab workflow

Select New file from the + menu to create a file.

Creating the pipeline file

Add the configuration and select Commit changes to save and enable the GitLab pipeline.

Use the configuration on the GitLab Workflow page.

Saving the pipeline configuration

3. Verify with an MR

Clone the repository

Clone the repository containing the GitLab pipeline, using its actual URL in place of the example git clone https://gitlab.com/....

Create a branch

Prepare the merge request in your terminal.

  1. Run cd repository to enter the cloned directory, replacing repository with its actual name.
  2. Run git checkout -b pr-test to create the pr-test branch.
  3. Create the following intentionally vulnerable files.

vuln_crypto.py

python
# Unsafe Crypto Algorithm + Hardcoded key
from Crypto.Cipher import DES
ENCRYPTION_KEY = b"weak_key"
cipher = DES.new(ENCRYPTION_KEY, DES.MODE_ECB)

vuln_exec.py

python
# Unsafe Flask RCE
from flask import Flask, request

app = Flask(__name__)

@app.route('/exec')
def unsafe_exec():
    code = request.args.get('code')
    eval(code)
    return "Dangerous Code executed"
  1. After creating the files, run:
text
git add . 
git commit -m "add tests"
git push origin pr-test
  1. Return to the project containing the GitLab workflow and select New merge request.
Opening a merge request

Select pr-test, then choose Compare branches and continue.

Selecting the test branch
  1. Check that comments appear as shown below.
XEIZE comments on the merge request
XEIZE finding details