Tag: email token flaw
1 article

GitLab Exposes Email Token Flaw, Enabling Unauthorized Code Pushes
GitLab has a security flaw that exposes a private email token, allowing unauthorized users to push code changes to projects - essentially giving anyone carte blanche to act on your behalf. This token, tied to your account, doesn't expire and grants access to all projects you have permission to open.