Skip to content

Passive scanner rules (alpha) version 26

Choose a tag to compare

@github-actions github-actions released this 16 Dec 16:05
ac1e066

Added

  • Add Java Serialized Object (JSO) Scanner.
  • Add Sub Resource Integrity Attribute Missing Scanner.

Changed

  • Fixed false positive when redirect destination is the same domain (Issue 5289).
  • CSP Missing and Feature Policy scan rule: Ignore missing headers on redirects unless Low threshold used.

Removed

  • The following scan rules were removed in being promoted to Beta:
    • Big Redirect Detected (Potential Sensitive Information Leak)
    • Content Security Policy (CSP) Header Not Set
    • Cookie Poisoning
    • Directory Browsing
    • Hash Disclosure
    • Heartbleed OpenSSL Vulnerability (Indicative)
    • HTTP Server Response Header Scanner
    • HTTP to HTTPS Insecure Transition in Form Post
    • HTTPS to HTTP Insecure Transition in Form Post
    • Open Redirect
    • PII Scanner
    • Retrieved from Cache
    • Reverse Tabnabbing
    • Strict-Transport-Security Header Scanner
    • User Controllable Charset
    • User Controllable HTML Element Attribute (Potential XSS)
    • User Controllable JavaScript Event (XSS)
    • X-Backend-Server Header Information Leak
    • X-ChromeLogger-Data (XCOLD) Header Information Leak