It was meant to make life simpler: a secret email address to which developers can send a message and create an issue in their GitLab project. But poor security defaults and a long-lived token embedded in the address mean that anyone who knows the address can potentially modify protected repositories. If project owners publish or leak these... Weiterlesen
Intelligence View
⚡ tsecurity.de Intelligence
GitLab issue email’s only security is obscurity
It was meant to make life simpler: a secret email address to which developers can send a message and create an issue in their GitLab project. But poor security defaults and a long-lived token embedded in the address mean that anyone who…
Reagiere als Erste:r — dein Feedback zählt!