doc/user/application_security/dast/browser/checks/798.91.md
The response body contains content that matches the pattern of a PlanetScale API service token was identified. Service tokens are created and assigned permissions depending on the allowed scope. A malicious actor with access to the service token is granted the same permissions that were assigned to this service token. Exposing this value could allow attackers to gain access to all resources granted by this token.
For general guidance on handling security incidents with regards to leaked keys, please see the GitLab documentation on Credential exposure to the internet.
To revoke a service token:
For more information, please see PlanetScale's documentation on service tokens.
| ID | Aggregated | CWE | Type | Risk |
|---|---|---|---|---|
| 798.91 | false | 798 | Passive | High |