Skip to content

Passive scanner rules (beta) version 31

Choose a tag to compare

@zapbot zapbot released this 27 Oct 13:01
· 6583 commits to main since this release
895169a

Added

  • The following scan rules were added, having been promoted from Alpha:
    • Content Cacheable
    • In Page Banner Info Leak
    • JS Function
    • JSO
    • Permissions Policy
    • Sub Resource Integrity Attribute

Changed

  • Update minimum ZAP version to 2.12.0.
  • Content Cacheability scan rule now has functionality to generate example alerts for documentation purposes (Issue 7502).

Removed

  • The following scan rules were removed, having been promoted to Release:
    • Big Redirects
    • Directory Browsing
    • Hash Disclosure
    • HeartBleed
    • Insecure Form Load
    • Insecure Form Post
    • Link Target
    • Modern App Detection
    • PII
    • Retrieved From Cache
    • Server Header Info Leak
    • Strict Transport Security
    • User Controlled Charset
    • User Controlled Cookie
    • User Controlled HTML Attributes
    • User Controlled Javascript Event
    • User Controlled Open Redirect
    • X-Backend-Server Information Leak
    • X-ChromeLogger-Data Info Leak