Skip to content

Active scanner rules (beta) version 32

Choose a tag to compare

@github-actions github-actions released this 27 Nov 11:06
8fed6a1

Changed

  • XML External Entity Attack scan rule changed to parse response body irrespective of the HTTP response status code. (Issue 6203)
  • XML External Entity Attack scan rule changed to skip only Remote File Inclusion Attack when Callback extension is not available.
  • Maintenance changes.
  • The Relative Path Confusion scan rule no longer treats 'href="#"' as a problematic use.

Fixed

  • Terminology.
  • Correct reason shown when the XML External Entity Attack scan rule is skipped.
  • SocketTimeoutException in the Proxy Disclosure scan rule.

Added

  • The following scan rules were promoted to Beta: Cloud Meta Data, .env File, Hidden Files, XSLT Injection (Issue 6211).

Removed

  • The following scan rules were removed and promoted to Release: ELMAH Information Leak, .htaccess Information Leak (Issue 6211).