
3/6/2018 · Jim Thavisouk
What this post added
This post details a security vulnerability where the `@gitlab.com` domain used for the "create new issues via email" feature could be abused by attackers. It outlines customer remediation steps to update email aliases and whitelisting to `@incoming.gitlab.com` and GitLab's strategy to update addresses and disable old ones. This is a security hardening measure for an existing feature.