Skip to content

Passive scanner rules version 52

Choose a tag to compare

@zapbot zapbot released this 12 Oct 14:39
· 5051 commits to main since this release
356484d

Fixed

  • The CSRF Countermeasures scan rule now skips responses that are not HTML (Issue 7890).
  • A potential NullPointerException when a CSP declared via META tag was invalid.

Changed

  • Update minimum ZAP version to 2.14.0.
  • CSP scan rule: Add deprecation warning for inclusion of prefetch-src (Issue 8077).