Leaked GitLab email tokens can open private code pipelines
Daily Cyber News: Leaked GitLab email tokens can open private code pipelines
A leaked GitLab project email address can let an outsider act with the token owner’s permissions. These addresses contain non-expiring incoming-mail tokens, and research found that the same account-level token may work across a user’s public and private projects. Someone who obtains an address could submit merge requests, push code where the user has permission, or trigger continuous integration jobs.
Key context: GitLab described the underlying behavior as intended, although it changed its interface and documentation to make the capabilities and I P restriction exception clearer.
For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.
Topics: cybersecurity news, cybersecurity, cyber risk, Leaked GitLab, Leaked, GitLab, email, tokens, open, private.