Skip to content

Active scanner rules version 35

Choose a tag to compare

@github-actions github-actions released this 02 Jun 09:55
3eb3a04

Changed

  • Update minimum ZAP version to 2.9.0.
  • Command Injection, Test Path Traversal, Test Cross Site ScriptV2 and Remote File Include rules are updated to include payloads for Null Byte Injection (Issue 3877).
  • Updated owasp.org references (Issue 5962).

Fixed

  • Fix typo in the help page.
  • Use correct risk (HIGH) in External Redirect, to run earlier in the scan.
  • Correct tech check in SQL Injection scan rule, which could cause it to be skipped with imported contexts (Issue 5918).