Skip to content

Passive scanner rules version 61

Choose a tag to compare

@zapbot zapbot released this 24 Sep 12:22
· 3623 commits to main since this release
2d06139

Changed

  • Maintenance changes.
  • Rename Mac OSX salted SHA-1 in the Hash Disclosure scan rule to "Salted SHA-1", reduce the associated alerts to Low risk and Low confidence, to align with other SHA related patterns it will only be evaluated a Low Threshold. (Note such matches may indicate leaks related but not limited to: MacOS X, Oracle, Tiger-192, Haval-192) (Issue 8624).
  • The Insecure JSF ViewState now includes example alert functionality for documentation generation purposes (Issue 6119).
  • The Absence of Anti-CSRF Tokens scan rule now only considers GET requests at Low Threshold (Issue 7741).