CyberHighSingle-sourceBuilding
6.9
GitLab email addresses expose privileged tokens, enabling supply chain attacks
Dark ReadingLO·2 days ago
Attackers can exploit publicly exposed GitLab project email addresses, which are designed to allow issue creation via email, to push code or issues to repositories. The exposure occurs through READMEs and support pages, enabling unauthorized actions. This highlights a security gap in GitLab's email-based contribution feature.