Skip to content

Releases: ryanvmorais/webvigil

WebVigil 1.1.0

Choose a tag to compare

@ryanvmorais ryanvmorais released this 09 Oct 18:59
3fa3e71

A minor release: new options, detector improvements and hardening, all backward compatible. No exit code, existing check id or JSON report field changes.

  • Single-page applications: --har seeds the crawl and the injection pass from a browser or proxy recording, so an app that builds its pages in JavaScript is no longer one empty page.
  • Detectors: a <select> is now fuzzed, --file-upload reaches servers that filter by part type, blind SQL injection is found when a field ships empty, and a GET form that changes state is flagged.
  • Targets: a one-label host (http://app:8000/, a Compose service name) or an IPv6 literal is accepted; [http] total_timeout_s bounds a whole request.
  • Dashboard and Web API: every page has a nonce-based Content-Security-Policy; the API refuses cross-origin state changes, and reports are served with nosniff and a sandbox policy.
  • Upgrade: pipx upgrade webvigil or docker pull ghcr.io/ryanvmorais/webvigil:1.1.0

Scan only systems you own or have permission to test. What is and is not promised across versions: docs/stability.md.

Full list of what changed in 1.1.0: CHANGELOG

WebVigil 1.0.4

Choose a tag to compare

@ryanvmorais ryanvmorais released this 09 Oct 00:41
b17fd1e

A patch release with one fix: a robots.txt, a sitemap or a page served by the scanned site can no longer keep a scan busy for a long time or make it use a lot of memory.

  • The crawl reads at most 20 sitemaps and 10,000 sitemap URLs, 20,000 links per page, 500 forms per page and 1,000 controls per form, and keeps at most 2,000 forms and a bounded set of URLs seen.
  • The pages fetched are the same while max_pages is within those limits, and a scan warning says when a limit was reached.
  • A link, a form or a sitemap past a limit is left out.
  • Upgrade with pip install -U webvigil or pull ghcr.io/ryanvmorais/webvigil:1.0.4. Nothing in the CLI, the exit codes, the configuration keys, the check ids or the JSON report changes.

Use WebVigil only on systems you own or are authorized in writing to test.

Security advisory: GHSA-63j8-4f3v-r77j

Full list of changes: CHANGELOG.md

WebVigil 1.0.3

Choose a tag to compare

@ryanvmorais ryanvmorais released this 08 Oct 21:15
d7e26af

A patch release with one fix: a page, a script or an API description served by the scanned site can no longer keep a scan busy for a long time or make it use a lot of memory.

  • The patterns of the library fingerprint (which run in the default Safe Mode), of the Active Mode signatures and of the host-header, TRACE and CSRF-confirmation passes are bounded, and they read the first 256 KiB of a body or script.
  • The OpenAPI import caps the size of the request bodies it builds from a schema.
  • A library marker or a framework message that appears only after the first 256 KiB of a body is no longer recognised; a request body for a very large schema is cut short.
  • Upgrade with pip install -U webvigil or pull ghcr.io/ryanvmorais/webvigil:1.0.3. Nothing in the CLI, the exit codes, the configuration keys, the check ids or the JSON report changes.

Use WebVigil only on systems you own or are authorized in writing to test.

Security advisory: GHSA-7cmg-mh2g-8rwv

Full list of changes: CHANGELOG.md

WebVigil 1.0.2

Choose a tag to compare

@ryanvmorais ryanvmorais released this 08 Oct 18:49
601743c

Patch release with one fix, in the error-page signatures of the information-disclosure check. The CLI, the exit codes, the configuration keys, the check ids and the JSON report do not change.

  • The patterns that recognise Java, Node.js and Python stack traces and the Django and Rails debug pages are bounded, so a page from the scanned site can no longer keep a scan busy for a long time in them. The signatures now read the first 256 KiB of a body: a framework error that appears only past that point is no longer recognised.
  • Upgrade: pipx upgrade webvigil, or docker pull ghcr.io/ryanvmorais/webvigil:1.0.2.

Scan only systems you own or have permission to test. The compatibility promise is in docs/stability.md.

Security advisory: GHSA-wxvq-cw49-p7f6

Full list of what changed in 1.0.2: CHANGELOG

WebVigil 1.0.1

Choose a tag to compare

@ryanvmorais ryanvmorais released this 08 Oct 15:07
cfa2e08

Patch release: it hardens the optional Web API and lifts the selectolax cap. The CLI, the exit codes, the configuration keys, the check ids and the JSON report do not change.

  • Web API: it refuses at start a pinned session_secret shorter than 32 characters and a * in cors_origins, and an unauthenticated request can no longer make it hold memory in proportion to its size (a body over 1 MiB is answered with 413, the login fields are capped). If you pinned a shorter secret, generate a longer one before upgrading.
  • Login takes the same time for a username that does not exist as for a wrong password, and an out-of-range scan id is a 422, not a 500.
  • HTML is parsed with the Lexbor backend of selectolax (selectolax>=1.0.0,<2); a full Active scan of the bundled test app gives the same findings.
  • Windows: a report redirected from stdout is UTF-8, so webvigil report can read it back.
  • Upgrade: pipx upgrade webvigil, or docker pull ghcr.io/ryanvmorais/webvigil:1.0.1.

Scan only systems you own or have permission to test. The compatibility promise is in docs/stability.md.

Security advisory: GHSA-vw64-75mj-x37q

Full list of what changed in 1.0.1: CHANGELOG

WebVigil 1.0.0

Choose a tag to compare

@ryanvmorais ryanvmorais released this 08 Oct 04:17
d12d822

First release of WebVigil: an open-source web application vulnerability scanner (DAST) for developers.

  • Safe Mode by default (passive, production-safe); Active Mode behind --mode active --authorized-by.
  • 50 checks (27 passive, 23 active), every active finding confirmed against a per-request baseline.
  • Reports in JSON (with a schema_version), SARIF 2.1.0, HTML and Markdown; --fail-on for CI.
  • Install: pipx install webvigil, or docker run --rm ghcr.io/ryanvmorais/webvigil scan <url>.

Scan only systems you own or have permission to test. What WebVigil does not do is in the
README's "Scope and limitations"; the compatibility promise is in docs/stability.md.

Full list of what is in 1.0.0: CHANGELOG