CyberSecurity News
A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
AI summary
A private email address provided by GitLab for filing issues can be used as a credential to push code and run CI jobs in a user's name. This email address can be found behind a button labeled "Email work item to this project" and is used to open issues in a project. If someone obtains this email address, they can email a patch that GitLab will commit in the user's name to any branch the user has push access to. This includes the main branch, and the attacker can also start CI/CD jobs that run under the user's identity. The email address is intended to allow users to file issues by email, but it poses a security risk if it falls into the wrong hands.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

