Unauthorized Access to CI/CD Infrastructure and Project Secrets via Compromised GitLab Runner Token

Disclosed by
oguzhan_00
Summary by oguzhan_00

A publicly exposed NASA GitLab Runner registration token allowed an external researcher to successfully register and authenticate an unauthorized runner within NASA’s SMCE CI/CD infrastructure. This demonstrated a real supply-chain security impact, as the compromised runner could potentially access CI/CD secrets and influence build processes, while further exploitation was intentionally avoided.
Best Regards,
oguzhan_00

Activity