Leaked GitLab issue email address lets anyone push code and run CI jobs as you
The private email address GitLab provides for filing issues by email acts as a credential. Anyone who obtains it can email a patch that GitLab commits in your name to any branch you can push to, including main, and can start CI/CD jobs that run as you.
- The email-to-issue address functions as a GitLab credential
- It allows committing patches to any branch, including main
- Attackers can trigger CI/CD jobs with the victim's permissions
- The address is shown behind the 'Email work item to this project' button
Read next
Security