Skip to content

Active scanner rules (beta) version 55

Compare
Choose a tag to compare
@zapbot zapbot released this 02 Sep 17:00
· 386 commits to main since this release
151c90e

Changed

  • The following scan rules now include example alert functionality for documentation generation purposes (Issue 6119):
    • Expression Language Injection
    • Cookie Slack Detector

Fixed

  • Potential false positives in the Source Code Disclosure - File Inclusion scan rule when responses are empty or the original message resulted in an error to start with (Issue 8517).
  • A spacing/punctuation issue in the Cookie Slack Detector scan rule, whereby the Other Info field would not have a space after colons and before lists of cookie names.