Johan Carlsson takes proving impact to the extreme by showing that a GitLab bug could've resulted in an attacker being able to:
- Trigger new and existing pipelines
- Overwrite variables
- Upload images for RCE
- Gain full access to all CI variables
- [INSERT IMAGINATION]