> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-based-access-controls/appsec-cicd-238.md).

# Project configured for group-wide access using job token

## Rule Details

|                       |                                |
| --------------------- | ------------------------------ |
| Cortex AppSec Rule ID | APPSEC\_CICD\_238              |
| Category              | Pipeline Based Access Controls |
| Severity              | MEDIUM                         |

## Impact

GitLab pipeline jobs are assigned a token that enables authentication to specific API endpoints. <https://docs.gitlab.com/ee/ci/jobs/ci\\_job\\_token> The token has the same permissions to access the API as the user who triggered the job. By compromising a third party and achieving code execution in a pipeline, attackers can exploit the permissions granted by the token to expand their attack and potentially compromise any projects accessible by the user that are not specifically restricted by the job token allow list.

## Recommended Solution - Buildtime

It is recommended to configure a project to restrict access from other job tokens through an allow list.

To Control access that other projects have to a project by enabling an allow list of approved projects:

1. In GitLab, browse to the Project **Settings** page.
2. Under **CI/CD**, expand **Token Access** and toggle the **Allow access to this project with a CI\_JOB\_TOKEN** button **ON**.
3. To add a project to the allow list, add the project name in the provided field and click **Add project**.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/pipeline-based-access-controls/appsec-cicd-238.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
