Tech News
← Home  ·  All topics

Aikido Security

1 GoKawiil brief on this topic

Aikido Security finds GitLab issue-creation email addresses can grant account-level access

Aikido Security published research showing that GitLab's per-user incoming email address, meant to let users create project issues via email, contains a non-expiring token that functions as an authentication and authorization credential. Because GitLab treats any message sent to that address as coming from its owner, exposure of the address alone can let an attacker create issues, submit merge requests, or send patch files across an organization's public and private projects without needing account credentials.