Skip to content

Active scanner rules (beta) version 57

Choose a tag to compare

@zapbot zapbot released this 15 Jan 10:11
· 2981 commits to main since this release
bdec152

Changed

  • Update minimum ZAP version to 2.16.0.
  • The following scan rules now use more specific CWE IDs:
    • Proxy Disclosure (Issue 8713)
    • Possible Username Enumeration (Issue 8715)
  • Remove double dot in skipped message of scan rules that use the Active Scan OAST service.

Fixed

  • Address exception when scanning a message without path with Possible Username Enumeration scan rule.
  • The WSTG alert tags on the HTTP Only Site scan rule.

Added

  • Standardized Scan Policy related alert tags on various rules.