Exposed GitLab project email addresses let attackers push code
Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. The addresses are part of a built-in GitLab feature called “Email work item to this project” and contain a long-lived token tied to the […]
