#unauthorizedcodepushes — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #unauthorizedcodepushes, aggregated by home.social.
-
GitLab Exposes Email Token Flaw, Enabling Unauthorized Code Pushes
GitLab has a security flaw that exposes a private email token, allowing unauthorized users to push code changes to projects - essentially giving anyone carte blanche to act on your behalf. This token, tied to your account, doesn't expire and grants access to all projects you have permission to open.
#Gitlab #EmailTokenFlaw #UnauthorizedCodePushes #SupplyChain #EmergingThreats