Plan
active
Exposed GitLab project email addresses let attackers push code
- Engineer — Plan: Audit all public-facing GitLab project documentation (READMEs, contributing guides, support pages) for exposed project email addresses and rotate or remove any found — no exploitation signals present, but the exposure is real and easy to enumerate at scale.
- SOC/IR — Learn: No IOCs, active exploitation evidence, or ATT&CK-mappable TTPs provided; the risk is a misconfiguration for engineers to remediate rather than a detection engineering task.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.