Kryptovaluta-ticker:
sysadmin fra Cyber Security News

GitLab Email Feature Vulnerability Lets Attackers Push Code Into Private Repositories

Guru Baran
4 hours ago
5 Visninger
0 Kommentarer
GitLab Email Feature Vulnerability Lets Attackers Push Code Into Private Repositories

GitLab’s “Email work item to this project” feature can become a repository-compromise primitive when its private address is exposed, according to research published by Aikido Security researcher Joe Leon on September 23, 2026. The address contains a long-lived glimt- incoming-email token that GitLab says does not expire and must remain secret. GitLab documentation confirms that anyone possessing it can create issues and merge requests as the token owner. Email work item option in GitLab (Image source: Aikido) The flaw extends far beyond issue spam. Although the interface presents a project-specific address, Aikido found that addresses generated for different projects embed the same account-level token. An attacker can...

Les hele artikkelen hos kilden.

Delta i diskusjonen — kommenter, stem og del lenker.

Registrer
Var dette nyttig?
Del:

Kommentarer (0)

Vennligst logg inn eller registrer deg for å delta i diskusjonen

Ingen kommentarer ennå. Bli den første til å kommentere!