A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
GitLab’s non-expiring incoming email token can let a holder commit code with a user’s permissions and trigger CI/CD jobs.
More info
