Exposed GitLab project email addresses let attackers push code

Exposed GitLab project email addresses let attackers push code
Aikido researchers found private GitLab incoming email addresses exposed in public READMEs, contributing guides, and support pages, creating a risk that attackers could abuse them to create issues, merge requests, or gain broader access. GitLab says these addresses are private and should be reset if leaked, while maintainers are urged to stop publishing them and review projects that exposed them. #GitLab #Aikido

Keypoints

  • Private GitLab incoming email addresses were found exposed in public project documentation.
  • Each address contains a long-lived token tied to the developer’s account.
  • An attacker could change the suffix to create merge requests instead of issues.
  • The attack may bypass IP restrictions and expose code, secrets, and private issues.
  • Project maintainers should remove exposed addresses and reset leaked tokens immediately.

Read More: https://www.bleepingcomputer.com/news/security/exposed-gitlab-project-email-addresses-let-attackers-push-code/