Skip to content

Passive scanner rules version 45

Choose a tag to compare

@zapbot zapbot released this 03 Jan 17:00
· 6266 commits to main since this release
d791e36

Changed

  • The Private Address Disclosure and Session ID in URL Rewrite scan rules now include example alert functionality for documentation generation purposes (Issue 6119 and 7100).
  • The Content Security Policy scan rule will now alert when "unsafe-eval" is allowed.
  • Maintenance changes.
  • The Salvation2 library used by the CSP scan rule was upgraded to v3.0.1. Alerts may now have an alert condition if the policy contains characters outside the accepted set.
  • The CSP scan rule now includes handling for policies defined in META tags, as well as two new alerts pertaining to those policies (Issue 7303).

Fixed

  • The Modern App Detection scan rule now ignores non-HTML files (Issue 7617).