|
227 | 227 | <name>Active scanner rules (beta)</name> |
228 | 228 | <description>The beta status Active Scanner rules</description> |
229 | 229 | <author>ZAP Dev Team</author> |
230 | | - <version>56</version> |
231 | | - <file>ascanrulesBeta-beta-56.zap</file> |
| 230 | + <version>57</version> |
| 231 | + <file>ascanrulesBeta-beta-57.zap</file> |
232 | 232 | <status>beta</status> |
233 | 233 | <changes><h3>Changed</h3> |
234 | 234 | <ul> |
235 | | -<li>Log exception details in Out of Band XSS scan rule.</li> |
236 | | -<li>Maintenance changes.</li> |
237 | | -<li>The Anti-CSRF Tokens Check scan rule now only considers GET requests at Low Threshold (Issue 7741).</li> |
| 235 | +<li>Update minimum ZAP version to 2.16.0.</li> |
| 236 | +<li>The following scan rules now use more specific CWE IDs: |
| 237 | +<ul> |
| 238 | +<li>Proxy Disclosure (Issue 8713)</li> |
| 239 | +<li>Possible Username Enumeration (Issue 8715)</li> |
| 240 | +</ul> |
| 241 | +</li> |
| 242 | +<li>Remove double dot in skipped message of scan rules that use the Active Scan OAST service.</li> |
238 | 243 | </ul> |
239 | 244 | <h3>Fixed</h3> |
240 | 245 | <ul> |
241 | | -<li>Address time-based false positives in Remote Code Execution - Shell Shock scan rule (Issue 8516).</li> |
| 246 | +<li>Address exception when scanning a message without path with Possible Username Enumeration scan rule.</li> |
| 247 | +<li>The WSTG alert tags on the HTTP Only Site scan rule.</li> |
| 248 | +</ul> |
| 249 | +<h3>Added</h3> |
| 250 | +<ul> |
| 251 | +<li>Standardized Scan Policy related alert tags on various rules.</li> |
242 | 252 | </ul></changes> |
243 | | - <url>https://github.com/zaproxy/zap-extensions/releases/download/ascanrulesBeta-v56/ascanrulesBeta-beta-56.zap</url> |
244 | | - <hash>SHA-256:e6dd4dc66fe79f192fae8e336e1708ca710eac190a04c79f1cd01e3fa9f2432c</hash> |
| 253 | + <url>https://github.com/zaproxy/zap-extensions/releases/download/ascanrulesBeta-v57/ascanrulesBeta-beta-57.zap</url> |
| 254 | + <hash>SHA-256:d2574f4a79137a5d3d0b1bb82563863a8c414bd13c9ef42e0084090e37337b03</hash> |
245 | 255 | <info>https://www.zaproxy.org/docs/desktop/addons/active-scan-rules-beta/</info> |
246 | 256 | <repo>https://github.com/zaproxy/zap-extensions/</repo> |
247 | | - <date>2024-09-24</date> |
248 | | - <size>1768903</size> |
249 | | - <not-before-version>2.15.0</not-before-version> |
| 257 | + <date>2025-01-15</date> |
| 258 | + <size>1777403</size> |
| 259 | + <not-before-version>2.16.0</not-before-version> |
250 | 260 | <dependencies> |
251 | 261 | <addons> |
252 | 262 | <addon> |
253 | 263 | <id>commonlib</id> |
254 | | - <version>>= 1.17.0 & < 2.0.0</version> |
| 264 | + <version>>= 1.29.0 & < 2.0.0</version> |
255 | 265 | </addon> |
256 | 266 | <addon> |
257 | 267 | <id>database</id> |
@@ -736,45 +746,41 @@ to find and add subdomains to the Sites Tree.</li> |
736 | 746 | <name>Custom Payloads</name> |
737 | 747 | <description>Ability to add, edit or remove payloads that are used i.e. by active scanners</description> |
738 | 748 | <author>ZAP Dev Team</author> |
739 | | - <version>0.13.0</version> |
740 | | - <file>custompayloads-beta-0.13.0.zap</file> |
741 | | - <status>beta</status> |
| 749 | + <version>0.14.0</version> |
| 750 | + <file>custompayloads-release-0.14.0.zap</file> |
| 751 | + <status>release</status> |
742 | 752 | <changes><h3>Changed</h3> |
743 | 753 | <ul> |
744 | | -<li>Update minimum ZAP version to 2.14.0.</li> |
| 754 | +<li>Promoted to Release status.</li> |
| 755 | +<li>Update minimum ZAP version to 2.16.0.</li> |
745 | 756 | <li>Maintenance changes.</li> |
746 | | -<li>Promoted to Beta.</li> |
| 757 | +<li>The superfluous/unused ID element of the custom payloads has been removed from the GUI and config.</li> |
| 758 | +<li>Now depends on the Common Library add-on.</li> |
747 | 759 | </ul> |
748 | 760 | <h3>Added</h3> |
749 | 761 | <ul> |
750 | | -<li>Initial API support: |
751 | | -<ul> |
752 | | -<li>Actions |
753 | | -<ul> |
754 | | -<li>Enable payloads.</li> |
755 | | -<li>Disable payloads.</li> |
756 | | -<li>Enable payload.</li> |
757 | | -<li>Disable payload.</li> |
758 | | -<li>Add payload.</li> |
759 | | -<li>Remove payload.</li> |
| 762 | +<li>Add help button to Options panel and add further detailed Help content.</li> |
760 | 763 | </ul> |
761 | | -</li> |
762 | | -<li>Views: |
| 764 | +<h3>Fixed</h3> |
763 | 765 | <ul> |
764 | | -<li>Payload categories.</li> |
765 | | -<li>Payloads (optionally filtered by category).</li> |
766 | | -</ul> |
767 | | -</li> |
768 | | -</ul> |
769 | | -</li> |
| 766 | +<li>The add-on will no longer attempt to save or load Payloads for which there is no Category.</li> |
| 767 | +<li>Ensure file is selected, exists, and is readable when attempting to import multiple payloads.</li> |
770 | 768 | </ul></changes> |
771 | | - <url>https://github.com/zaproxy/zap-extensions/releases/download/custompayloads-v0.13.0/custompayloads-beta-0.13.0.zap</url> |
772 | | - <hash>SHA-256:07c571e121291980add70fad1b64933382742e93959c7dd470426b4fb111921e</hash> |
| 769 | + <url>https://github.com/zaproxy/zap-extensions/releases/download/custompayloads-v0.14.0/custompayloads-release-0.14.0.zap</url> |
| 770 | + <hash>SHA-256:fe99e67a3a456c70a25c35e5d25961c1dca417d2c94124316c2ea26965009ec2</hash> |
773 | 771 | <info>https://www.zaproxy.org/docs/desktop/addons/custom-payloads/</info> |
774 | 772 | <repo>https://github.com/zaproxy/zap-extensions/</repo> |
775 | | - <date>2023-11-10</date> |
776 | | - <size>246425</size> |
777 | | - <not-before-version>2.14.0</not-before-version> |
| 773 | + <date>2025-01-15</date> |
| 774 | + <size>292156</size> |
| 775 | + <not-before-version>2.16.0</not-before-version> |
| 776 | + <dependencies> |
| 777 | + <addons> |
| 778 | + <addon> |
| 779 | + <id>commonlib</id> |
| 780 | + <version>>= 1.17.0 & < 2.0.0</version> |
| 781 | + </addon> |
| 782 | + </addons> |
| 783 | + </dependencies> |
778 | 784 | </addon_custompayloads> |
779 | 785 | <addon>database</addon> |
780 | 786 | <addon_database> |
@@ -2373,20 +2379,30 @@ to find and add subdomains to the Sites Tree.</li> |
2373 | 2379 | <name>Passive scanner rules (beta)</name> |
2374 | 2380 | <description>The beta status Passive Scanner rules</description> |
2375 | 2381 | <author>ZAP Dev Team</author> |
2376 | | - <version>41</version> |
2377 | | - <file>pscanrulesBeta-beta-41.zap</file> |
| 2382 | + <version>42</version> |
| 2383 | + <file>pscanrulesBeta-beta-42.zap</file> |
2378 | 2384 | <status>beta</status> |
2379 | | - <changes><h3>Fixed</h3> |
| 2385 | + <changes><h3>Changed</h3> |
| 2386 | +<ul> |
| 2387 | +<li>Update minimum ZAP version to 2.16.0.</li> |
| 2388 | +<li>Updated help with specific Category identifier for use with the Custom Payloads add-on for the &quot;Dangerous JS Functions&quot; rule.</li> |
| 2389 | +</ul> |
| 2390 | +<h3>Fixed</h3> |
| 2391 | +<ul> |
| 2392 | +<li>Fix typo in log message.</li> |
| 2393 | +<li>Fix Insufficient Site Isolation scan rule check that filters responses based on whether a response is a success or not.</li> |
| 2394 | +</ul> |
| 2395 | +<h3>Changed</h3> |
2380 | 2396 | <ul> |
2381 | | -<li>A possible false positive condition with the Dangerous JS Functions scan rule with substrings in certain circumstances (Issue 8553).</li> |
| 2397 | +<li>Maintenance changes.</li> |
2382 | 2398 | </ul></changes> |
2383 | | - <url>https://github.com/zaproxy/zap-extensions/releases/download/pscanrulesBeta-v41/pscanrulesBeta-beta-41.zap</url> |
2384 | | - <hash>SHA-256:afb76940929bf4f3bf2ab4a2d0a0fa9d50ef834969b551c5397459746caf6e76</hash> |
| 2399 | + <url>https://github.com/zaproxy/zap-extensions/releases/download/pscanrulesBeta-v42/pscanrulesBeta-beta-42.zap</url> |
| 2400 | + <hash>SHA-256:91626262fbe76d097b508a2e85b3192c8b12645dfb82387715ac12358989d562</hash> |
2385 | 2401 | <info>https://www.zaproxy.org/docs/desktop/addons/passive-scan-rules-beta/</info> |
2386 | 2402 | <repo>https://github.com/zaproxy/zap-extensions/</repo> |
2387 | | - <date>2024-09-02</date> |
2388 | | - <size>677612</size> |
2389 | | - <not-before-version>2.15.0</not-before-version> |
| 2403 | + <date>2025-01-15</date> |
| 2404 | + <size>678315</size> |
| 2405 | + <not-before-version>2.16.0</not-before-version> |
2390 | 2406 | <dependencies> |
2391 | 2407 | <addons> |
2392 | 2408 | <addon> |
@@ -3168,27 +3184,33 @@ to find and add subdomains to the Sites Tree.</li> |
3168 | 3184 | <name>Technology Detection</name> |
3169 | 3185 | <description>Technology detection using various fingerprints and identifiers.</description> |
3170 | 3186 | <author>ZAP Dev Team</author> |
3171 | | - <version>21.43.0</version> |
3172 | | - <file>wappalyzer-release-21.43.0.zap</file> |
| 3187 | + <version>21.44.0</version> |
| 3188 | + <file>wappalyzer-release-21.44.0.zap</file> |
3173 | 3189 | <status>release</status> |
3174 | 3190 | <changes><h3>Changed</h3> |
3175 | 3191 | <ul> |
3176 | 3192 | <li>Updated with enthec upstream icon and pattern changes.</li> |
3177 | | -<li>Maintenance changes.</li> |
| 3193 | +<li>Update minimum ZAP version to 2.16.0.</li> |
| 3194 | +<li>Depend on Passive Scanner add-on (Issue 7959).</li> |
| 3195 | +<li>The scan rule no longer sets a CWE for alerts (Issue 8733).</li> |
3178 | 3196 | </ul></changes> |
3179 | | - <url>https://github.com/zaproxy/zap-extensions/releases/download/wappalyzer-v21.43.0/wappalyzer-release-21.43.0.zap</url> |
3180 | | - <hash>SHA-256:f5bf3028d5a9bc262f522b920c9012a542d84e75b4429919c3eeb12851127c7b</hash> |
| 3197 | + <url>https://github.com/zaproxy/zap-extensions/releases/download/wappalyzer-v21.44.0/wappalyzer-release-21.44.0.zap</url> |
| 3198 | + <hash>SHA-256:b740a362994d4d21ec06be7b96889bb82c9743b9c2baecd8682c3758dd9f82bc</hash> |
3181 | 3199 | <info>https://www.zaproxy.org/docs/desktop/addons/technology-detection/</info> |
3182 | 3200 | <repo>https://github.com/zaproxy/zap-extensions/</repo> |
3183 | | - <date>2024-11-25</date> |
3184 | | - <size>19759181</size> |
3185 | | - <not-before-version>2.15.0</not-before-version> |
| 3201 | + <date>2025-01-15</date> |
| 3202 | + <size>20162575</size> |
| 3203 | + <not-before-version>2.16.0</not-before-version> |
3186 | 3204 | <dependencies> |
3187 | 3205 | <addons> |
3188 | 3206 | <addon> |
3189 | 3207 | <id>commonlib</id> |
3190 | 3208 | <version>>= 1.17.0 & < 2.0.0</version> |
3191 | 3209 | </addon> |
| 3210 | + <addon> |
| 3211 | + <id>pscan</id> |
| 3212 | + <version>>= 0.1.0 & < 1.0.0</version> |
| 3213 | + </addon> |
3192 | 3214 | </addons> |
3193 | 3215 | </dependencies> |
3194 | 3216 | </addon_wappalyzer> |
|
0 commit comments