Skip to content

Passive scanner rules version 41

Choose a tag to compare

@zapbot zapbot released this 24 Jun 16:27
· 7216 commits to main since this release
828f852

Changed

  • Maintenance changes.
  • The "Viewstate without MAC Signature (Unsure)" alert will now only be raised at Low Alert Threshold (Issue 7230).
  • The Content Security Policy scan rule will now alert when "unsafe-hashes" are allowed.

Fixed

  • Correct parameter and evidence for Cookie without SameSite Attribute when SAMESITE was set to None (Issue 7358).