Repository navigation
Highlights
JWT attack checks (powered by JWTop)
Six new automated checks, all auto-run when they apply to the token under test:
- Algorithm confusion / HMAC confusion
- Psychic signature (CVE-2022-21449)
jwkheader injectionjkuheader injectionx5cheader injectionx5uheader injection
Severity-threshold check pruning
New flag --only-scans-above-threshold (default false). Skips any check whose max possible CVSS is below --severity-threshold before the scan runs. Since every check that then runs can reach the threshold.
Engine refactor: harnessx + reportx
Scan execution now runs on cerberauth/harnessx and reporting on cerberauth/reportx.
Other
- Go 1.27 (build/Docker/CI).
Breaking changes
servecommand removed. The HTTP server (api/ package, all vulnapi serve endpoints) was not properly designed and has been removed. vulnapi serve now just prints a deprecation notice and exits 0. The server is deprecated for now, pending a new implementation. Track progress / share ideas: #303- HTTP security-header check IDs changed. misconfiguration.http_headers is now a parent covering individual sub-checks with new IDs (http_headers_csp_missing, http_headers_hsts_missing, http_headers_cors_missing, http_headers_cors_wildcard, http_headers_frame_options_missing, http_headers_content_options_missing, http_headers_csp_frame_ancestors_missing, …). CI configs filtering by the old granular IDs must be updated. Excluding the parent misconfiguration.http_headers still skips all of them.
- Report output produced by reportx. Anyone parsing JSON/YAML reports should re-validate against the new output.
What's Changed
- fix: golang lint issues by @emmanuelgautier in #295
- docs: add missing docs and update docs related to jwt by @emmanuelgautier in #294
- chore(deps): update actions/checkout action to v7 by @renovate[bot] in #293
- feat: update dependencies by @emmanuelgautier in #296
- docs: translate docs in french by @emmanuelgautier in #298
- chore(deps): update actions/setup-go action to v7 by @renovate[bot] in #299
- Refactor using harnessx and reportx by @emmanuelgautier in #301
- Deprecate serve command and remove unfinished HTTP server by @emmanuelgautier in #304
- Only report scan results above severity threshold by @emmanuelgautier in #307
- Upgrade golang 1.27 by @emmanuelgautier in #308
- Add JWTop crack jwt-psychic-signature, jwt-jwk-injection, jwt-jku-injection, jwt-x5c-injection, jwt-x5u-injection and hmac-confusion checks by @emmanuelgautier in #309
- Scan VAmPI using openapi.json by @emmanuelgautier in #310
Full Changelog: v0.9.0...v0.10.0