Active scanner rules (beta) version 57
·
2981 commits
to main
since this release
Changed
- Update minimum ZAP version to 2.16.0.
- The following scan rules now use more specific CWE IDs:
- Proxy Disclosure (Issue 8713)
- Possible Username Enumeration (Issue 8715)
- Remove double dot in skipped message of scan rules that use the Active Scan OAST service.
Fixed
- Address exception when scanning a message without path with Possible Username Enumeration scan rule.
- The WSTG alert tags on the HTTP Only Site scan rule.
Added
- Standardized Scan Policy related alert tags on various rules.