Leaked GitLab Email Tokens Can Reach Code, Secrets and CI/CD Pipelines
Security researchers have uncovered a GitLab behavior that could let attackers use a leaked project email address to push code, trigger CI/CD jobs and reach other repositories accessible to the address owner. Aikido Security researcher Joe Leon detailed the attack path this week in a blog post…
Sources
- T2Leaked GitLab Email Tokens Can Reach Code, Secrets and CI/CD PipelinesDevOps.com / Cloud Native Now