doc/user/application_security/dast/browser/checks/798.109.md
The response body contains content that matches the pattern of a Slack bot user OAuth token was identified. A Slack app's capabilities and permissions are governed by the scopes it requests. A full list of permissions can be found in Slack's scopes documentation. A malicious actor with access to this token can execute functionality that was assigned to it. Exposing this value could allow attackers to gain access to all resources granted by this token.
For general guidance on handling security incidents with regards to leaked keys, please see the GitLab documentation on Credential exposure to the internet.
To revoke a Slack bot user OAuth token (Note: This requires all users to re-authorize your application):
For more information, please see Slack's documentation on OAuth
| ID | Aggregated | CWE | Type | Risk |
|---|---|---|---|---|
| 798.109 | false | 798 | Passive | High |