GitLab Email Token Vulnerability Exposes CI/CD Pipelines
A seemingly mundane feature designed for emailing issue tasks has proven to be alarmingly akin to a fully privileged account, belying its innocuous interface. Joe Leon from Aikido Security demonstrated that a private GitLab...