A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
The Hacker News published a report titled "A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You." According to the headline, a leaked GitLab issue email address allows anyone to push code and run CI jobs as the affected user. The source text supplied for this item consists of the headline and embedded font styling from the article page, so the excerpt does not include the underlying technical mechanism, the GitLab version or deployment type involved, any CVE identifier, or a vendor response. Because the available text is limited to the headline, this digest is restricted to what that headline states: an email address associated with GitLab issues was leaked, and that leak is described as enabling unauthorized code pushes and CI job execution under another user's identity. No details are provided about how the address is obtained, which GitLab editions or configurations are affected, whether the issue has been reported to GitLab, or whether a fix exists. Readers should treat the specifics beyond the headline as unverified by this source text.
The headline states that a leaked GitLab issue email address lets anyone push code and run CI jobs as the affected user, exposing repository and pipeline access.