Skip to content

Passive scanner rules version 25

Choose a tag to compare

@github-actions github-actions released this 16 Dec 15:50
ac1e066

Changed

  • Content Security Policy scan rule: Update to Salvation 2.7.0, add handling for script-src-elem, script-src-attr, style-src-elem, and style-src-attr (Issue 5459).
  • Minimum ZAP version is now 2.8.0.

Added

  • The following scan rules were added, promoted from Beta to Release:
    • Cookie Without SameSite Attribute
    • Cross Domain Misconfiguration
    • Information Disclosure: In URL
    • Information Disclosure: Referrer
    • Information Disclosure: Suspicious Comments
    • Server Leaks Information via "X-Powered-By" HTTP Response Header Field(s)
    • Timestamp Disclosure
    • Username Hash Found
    • X-AspNet-Version Response Header Scanner
    • X-Debug-Token Information Leak