Skip to content

Releases: SasanLabs/VulnerableApp

VulnerableApp-1.12.0

18 Dec 04:43
82d82d8
Compare
Choose a tag to compare

✨ Newer Feature

🚀 Integrations

🧪 Addition of Tests

🐞 Fixes

  • Fixed jibDockerBuild command for local testing based on Multi-Platform build in #462
  • Fixed file upload directory creation when system root directory is not writable by application. #449 by @tkomlodi in #453
  • Mocked network calls made in SSRFVulnerabilityTest fixing local build errors by @tkomlodi in #447

New Contributors

Thanks a lot for all the amazing contributions.

Full Changelog: 1.11.0...1.12.0

VulnerableApp-1.11.0

14 Aug 02:25
07c3842
Compare
Choose a tag to compare

VulnerableApp-1.10.0

03 Aug 16:22
4a53cbe
Compare
Choose a tag to compare

This release includes:

  1. Onboarding to new User Interface for Owasp VulnerableApp-Facade
  2. Addition of Content-Disposition based File Upload attack
  3. Introduction to 'Secure' and 'Unsecure' marker for vulnerability levels
  4. Introduction to a better descriptive payload for SQL Injections
  5. Removed sample values from Annotation
  6. Addition of expected_issues.csv file which contains the vulnerabilities presents in VulnerableApp and is used by SAST tools to evaluate themselves.

Special thanks to contributors:

  1. @nowakkamil
  2. @marcin-wrotecki
  3. @o0o-v4mp1r3-o0o
  4. @agigleux
  5. @preetkaran20

For Docker-based installation please use the following URL:
https://hub.docker.com/r/sasanlabs/owasp-vulnerableapp

Pull the image by running the following command:

docker pull sasanlabs/owasp-vulnerableapp
For running vulnerable app as docker container: docker run -p 9090:9090 --name=owasp-vulnerableapp sasanlabs/owasp-vulnerableapp:latest

Hacktoberfest contributions plus Open Redirect Vulnerability

16 Nov 16:23
f5334e8
Compare
Choose a tag to compare

This release includes:

  1. Added Open Redirect Vulnerability Http Status Code 3XX based
  2. Special thanks to Hacktoberfest and all the awesome contributions made by contributors, highlights:
    2.1 @devabhishekpal , Designed an amazing Logo for the project
    2.2 @hexxdump , First ever article on the project
    2.3 @pavluchenko , Removing Maven and its related dependencies
    2.4 @fengyuanyang , Introduced unit-tests to the project
    2.5 @Nimanita @hritikgupta for improving error pages and documentation

Very glad to inform that we have reached a milestone of 75 Vulnerabilities with this release.

For Docker based installation please use following URL:
https://hub.docker.com/r/sasanlabs/owasp-vulnerableapp

Pull the image by running following command:

docker pull sasanlabs/owasp-vulnerableapp
For running vulnerable app as docker container: docker run -p 9090:9090 --name=owasp-vulnerableapp sasanlabs/owasp-vulnerableapp:latest

Major release with Framework Revamp and 2 New vulnerability addition

02 Oct 11:56
cccfec7
Compare
Choose a tag to compare

This release comprise of addition of 2 new Vulnerabilities:

  1. File Upload Vulnerability
  2. XXE
    Also we have revamped the entire backend framework with more generic and easy to use approach so that new vulnerabilities addition is quite easy.
    Along with these, in this release we have reduced the Docker Size by 20-25 MB (using jib suggested by @hemantgs ).
    We have also updated the documentation and a new website is added.

This is a major release with 141 commits, with 2,853 additions and 1,709 deletions.
Thanks to all the contributors:

  1. @preetkaran20
  2. @hemantgs
  3. @hritikgupta

For Docker based installation please use following URL:
https://hub.docker.com/r/sasanlabs/owasp-vulnerableapp

Pull the image by running following command:

docker pull sasanlabs/owasp-vulnerableapp
For running vulnerable app as docker container: docker run -p 9090:9090 --name=owasp-vulnerableapp sasanlabs/owasp-vulnerableapp:latest

Adding Persistent XSS vulnerability

08 Aug 20:04
25e5514
Compare
Choose a tag to compare

This release comprise of addition of Persistent XSS Vulnerability.

For Docker based installation please use following URL:
https://hub.docker.com/r/sasanlabs/owasp-vulnerableapp

Pull the image by running following command: docker pull sasanlabs/owasp-vulnerableapp
For running vulnerable app as docker container: docker run -p 9090:9090 --name=owasp-vulnerableapp sasanlabs/owasp-vulnerableapp:latest

Adding Path Traversal and Command Injection Vulnerabilities

01 Aug 20:48
b901450
Compare
Choose a tag to compare

Addition of 2 new vulnerabilities along with there UI.

For Docker based installation please use following URL:
https://hub.docker.com/r/sasanlabs/owasp-vulnerableapp

Pull the image by running following command: docker pull sasanlabs/owasp-vulnerableapp
For running vulnerable app as docker container: docker run -p 9090:9090 --name=owasp-vulnerableapp sasanlabs/owasp-vulnerableapp:latest

Vulnerability Scanning Tools Integration

21 Jul 20:45
9ac1a78
Compare
Choose a tag to compare

This release comprise of:

  1. Addition of sitemap.xml endpoint
  2. Addition of scanner and scanner/metadata endpoint for Vulnerability Scanning Tools Integration.
  3. Small UI fixes.

For Docker based installation please use following URL:
https://hub.docker.com/r/sasanlabs/owasp-vulnerableapp

Pull the image by running following command: docker pull sasanlabs/owasp-vulnerableapp
For running vulnerable app as docker container: docker run -p 9090:9090 --name=owasp-vulnerableapp sasanlabs/owasp-vulnerableapp:latest

Release 1.0.4

06 Jul 19:14
db29231
Compare
Choose a tag to compare

This release comprise of:

  1. SQL Injection vulnerability
  2. Few Fixes and Addition of Vulnerabilities
  3. UI design modifications and Button animation
  4. Spotless integration for code format

For Docker based installation please use following URL:
https://hub.docker.com/r/sasanlabs/owasp-vulnerableapp

Pull the image by running following command: docker pull sasanlabs/owasp-vulnerableapp
For running vulnerable app as docker container: docker run -p 9090:9090 --name=owasp-vulnerableapp sasanlabs/owasp-vulnerableapp:latest

New Version with some fixes and new theme

03 May 20:32
c5b6fa0
Compare
Choose a tag to compare

Very excited to announce the new version. This version is a minor release where i am adding new theme to vulnerableApp and little bit platform building at UI side is done.
Hope this will give more indications on where this project is heading towards.

There are many things which are left and we are working very hard on fulfilling them.

Waheguru Guru Nanak Patshah mehar kro ... !!! Sasan On work !!!