doc/user/application_security/dast/browser/checks/798.143.md
The response body contains content that matches the pattern of a deprecated GitLab Runner registration token was identified. These tokens allow users to register a runner with the selected project. A malicious actor with access to this token can add a custom runner to the pipeline and possibly compromise the repository if the runner was used. Exposing this value could allow attackers to gain access to all resources granted by this token.
For general guidance on handling security incidents with regards to leaked keys, please see the GitLab documentation on Credential exposure to the internet.
To rotate a runner registration token:
For more information, please see GitLabs documentation on using runner authentication tokens instead.
| ID | Aggregated | CWE | Type | Risk |
|---|---|---|---|---|
| 798.143 | false | 798 | Passive | High |