Skip to content

v0.10.0

Latest

Choose a tag to compare

@emmanuelgautier emmanuelgautier released this 30 Aug 09:21
· 8 commits to main since this release
6a783b9

Highlights

JWT attack checks (powered by JWTop)

Six new automated checks, all auto-run when they apply to the token under test:

  • Algorithm confusion / HMAC confusion
  • Psychic signature (CVE-2022-21449)
  • jwk header injection
  • jku header injection
  • x5c header injection
  • x5u header injection

Severity-threshold check pruning

New flag --only-scans-above-threshold (default false). Skips any check whose max possible CVSS is below --severity-threshold before the scan runs. Since every check that then runs can reach the threshold.

Engine refactor: harnessx + reportx

Scan execution now runs on cerberauth/harnessx and reporting on cerberauth/reportx.

Other

  • Go 1.27 (build/Docker/CI).

Breaking changes

  • serve command removed. The HTTP server (api/ package, all vulnapi serve endpoints) was not properly designed and has been removed. vulnapi serve now just prints a deprecation notice and exits 0. The server is deprecated for now, pending a new implementation. Track progress / share ideas: #303
  • HTTP security-header check IDs changed. misconfiguration.http_headers is now a parent covering individual sub-checks with new IDs (http_headers_csp_missing, http_headers_hsts_missing, http_headers_cors_missing, http_headers_cors_wildcard, http_headers_frame_options_missing, http_headers_content_options_missing, http_headers_csp_frame_ancestors_missing, …). CI configs filtering by the old granular IDs must be updated. Excluding the parent misconfiguration.http_headers still skips all of them.
  • Report output produced by reportx. Anyone parsing JSON/YAML reports should re-validate against the new output.

What's Changed

Full Changelog: v0.9.0...v0.10.0