CyberNotableSingle-source
5.1
Exposed GitLab project emails enable unauthorized code pushes
BleepingComputerLO·1 day ago
GitLab automatically assigns incoming email addresses to each user that contain highly privileged access tokens. Attackers can weaponize these tokens to compromise accounts and potentially launch supply chain attacks. The vulnerability is confirmed by the source, but exploitation details and affected versions remain unclear.