Skip to content

v1.1.22 beta 3

Pre-release
Pre-release

Choose a tag to compare

@bitterpanda63 bitterpanda63 released this 26 Nov 13:32
· 71 commits to main since this release
c8fd61b

What's Changed

  • send attack events even without a context for stored ssrf
  • report query parameters in url during attack for Spring MVC & Javalin
  • run attack wave detection after req, so user data can be reported.
  • respect protection forced off when scanning for (stored) ssrf
  • perf: re-use scanner instances to avoid unnecessary gc
  • perf: caches hostname, host ip, os & platform