GitLab email tokens allow code pushes and CI execution without authentication
Aikido Security reveals that leaked GitLab issue email addresses can be used to push code to main branches and run CI jobs, bypassing IP restrictions and two-factor authentication.

