[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDD3BXOLO6CTWjLMXoOBHBsNo-X52YAOlg--gmXT2OtU":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"9ce73bca-5ad7-40e0-ba61-ec06e03a69d6","gitlab-email-tokens-enable-unauthorized-code-pushes-via-exposed-addresses","8e112bfa-3140-4f38-b894-6529304f5516","GitLab Email Tokens Enable Unauthorized Code Pushes via Exposed Addresses","GitLab project email addresses, designed for bug report submission, inadvertently contain long-lived authentication tokens that function as credentials — creating a serious access control flaw when exposed publicly. Attackers discovered that simply modifying the '-issue' suffix to '-merge-request' in these addresses allows them to submit merge requests and push code to private repositories, entirely bypassing IP-based restrictions. This matters because long-lived tokens with broad implicit trust effectively become skeleton keys when leaked, enabling source code theft and secrets exposure. The core failure is a combination of poor secret hygiene (publishing email addresses containing tokens) and insufficient token scoping, compounding the risk that no expiration mechanism limits the window of exploitation.","**Immediate actions:**\n- Audit all public-facing documentation, READMEs, and issue trackers to identify and remove any exposed GitLab project email addresses.\n- Immediately reset any compromised or publicly exposed email ingest tokens via GitLab project settings.\n- Disable email-based code submission features on any project that does not explicitly require them.\n\n**Long-term improvements:**\n- Replace long-lived static tokens with short-lived, scoped credentials and enforce automatic token rotation policies.\n- Implement a secrets scanning pipeline (e.g., GitLab Secret Detection, Gitleaks) to detect token leakage in commits, issues, and wikis before they are published.\n- Establish a formal configuration baseline for all GitLab projects that includes required privacy and access settings as part of project provisioning.\n\n**Detection measures:**\n- Enable and monitor GitLab audit logs for unexpected merge requests or code pushes originating from email-based submission channels.\n- Set up alerts for any merge requests submitted via email integration that originate from unrecognized or external senders.\n- Periodically review active project tokens and revoke any that are unused, undocumented, or older than a defined threshold.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 5: Account Management","CIS Control 18: Penetration Testing","NIST SP 800-53 AC-2: Account Management","NIST SP 800-53 AC-6: Least Privilege","NIST SP 800-53 IA-5: Authenticator Management","NIST SP 800-53 CM-6: Configuration Settings","NIST SP 800-53 AU-6: Audit Record Review, Analysis, and Reporting","OWASP API Security Top 10: API2 - Broken Authentication","GDPR Article 32: Security of Processing (for EU-hosted repositories containing personal data)","published","2026-09-24T20:21:35.100242+00:00","2026-09-24T20:21:34.81+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fexposed-gitlab-project-email-addresses-let-attackers-push-code\u002F","exposed-gitlab-project-email-addresses-let-attackers-push-code-d8d3bf","Exposed GitLab project email addresses let attackers push code",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":43,"name":44,"slug":45,"description":46,"color":47},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]