Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

GitLab inbound email issue notification

Blog post from GitLab

Post Details
Company
Date Published
Author
Jim Thavisouk
Word Count
199
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitLab.com is addressing a security vulnerability related to the feature allowing users to create new issues via email, which is managed by Service Desk using the @gitlab.com domain. An attacker could exploit this feature to perform unauthorized actions, impacting users who utilize the email issue creation, Reply by Email, and Service Desk functionalities. To mitigate this issue, GitLab is advising users to update their email aliases and domain whitelisting from @gitlab.com to @incoming.gitlab.com. The company plans to disable the use of @gitlab.com for these purposes by April 31, 2018, and will reject incoming emails sent to the old addresses. GitLab is actively reaching out to affected users to ensure compliance with these changes by April 17, 2018.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.