Skip to main content

Tag: unauthorized code pushes

1 article

GitLab project dashboard on laptop with cursor over email button and partially obscured email address.

GitLab Exposes Email Token Flaw, Enabling Unauthorized Code Pushes

GitLab has a security flaw that exposes a private email token, allowing unauthorized users to push code changes to projects - essentially giving anyone carte blanche to act on your behalf. This token, tied to your account, doesn't expire and grants access to all projects you have permission to open.

Analyst 207