SECURITY·중요도 9·2026. 09. 23.·The Hacker News
A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
── KO ──────────────────
GitLab의 비공식 이메일 주소가 노출되어 권한이 없는 사용자가 코드를 푸시할 수 있는 취약점이 발생했습니다.
GitLab의 비공식 이메일 주소가 공개되어 누구나 이를 통해 사용자의 이름으로 패치를 이메일로 전송하고, 해당 프로젝트의 브랜치에 푸시 및 CI/CD 작업을 실행할 수 있는 위험이 존재합니다. 사용자는 이 이메일 주소를 통해 프로젝트에 문제를 제기할 수 있으며, 이는 보안 위협으로 작용할 수 있습니다. 따라서 사용자들은 이 유출된 이메일 주소에 대해 주의를 기울여야 합니다.
── EN ──────────────────
A leaked GitLab email address allows unauthorized users to push code and run CI jobs as you.
The leaked private email address GitLab provides for users to file issues can lead to serious security risks, allowing anyone who obtains it to send patches in your name. This means they could push changes to any branch you have permission for, including the main branch, and initiate CI/CD jobs as if they were you. Users are advised to pay attention to this security vulnerability.