v1.1.22 beta 3
Pre-release
Pre-release
·
71 commits
to main
since this release
What's Changed
- send attack events even without a context for stored ssrf
- report query parameters in url during attack for Spring MVC & Javalin
- run attack wave detection after req, so user data can be reported.
- respect protection forced off when scanning for (stored) ssrf
- perf: re-use scanner instances to avoid unnecessary gc
- perf: caches hostname, host ip, os & platform