Skip to content

Passive scanner rules version 44

Choose a tag to compare

@zapbot zapbot released this 27 Oct 11:01
· 6591 commits to main since this release
c4779b8

Added

  • The following scan rules were added, having been promoted from Beta:
    • Big Redirects
    • Directory Browsing
    • Hash Disclosure
    • HeartBleed
    • Insecure Form Load
    • Insecure Form Post
    • Link Target
    • Modern App Detection
    • PII
    • Retrieved From Cache
    • Server Header Info Leak
    • Strict Transport Security
    • User Controlled Charset
    • User Controlled Cookie
    • User Controlled HTML Attributes
    • User Controlled Javascript Event
    • User Controlled Open Redirect
    • X-Backend-Server Information Leak
    • X-ChromeLogger-Data Info Leak

Changed

  • Update minimum ZAP version to 2.12.0.
  • The Server Header Information Leak scan rule now has functionality to generate example alerts for documentation purposes (Issue 6119).
  • Maintenance changes.