Skip to content

Active scanner rules version 70

Choose a tag to compare

@zapbot zapbot released this 09 Jan 17:31
· 3022 commits to main since this release
bc5aa79

Changed

  • Update minimum ZAP version to 2.16.0.
  • Updated help with specific Category identifiers for use with the Custom Payloads add-on for rules:
    • Hidden File Finder
    • User Agent Fuzzer
  • Now depends on minimum Common Library version 1.29.0.
  • Add the OUT_OF_BAND alert tag to the following scan rules:
    • Server Side Template Injection (Blind)
    • XML External Entity Attack
  • Cloud Metadata Attack scan rule is improved to support GCP, Azure, and OCI.
  • Remove double dot in skipped message of a scan rule that uses the Active Scan OAST service.

Fixed

  • A situation where the Server-Side Template Injection (SSTI) scan rule might result in false positives related to the Go payloads (Issue 8622).
  • False Positives in Cloud Metadata Attack scan rule (Issue 8514).

Added

  • Standardized Scan Policy related alert tags on the rule.