Changelogs

Acunetix 360 On-Demand

RSS Feed

v24.11.0 - 12 Nov 2024

This release includes new features and security checks, improvements, and bug fixes.

This update includes changes to the internal agents. The internal scan agent’s current version is 24.11.0. The internal authentication verifier agent’s current version is 24.11.0.

New Features

  • API Discovery now supports working with RAML specs from Mulesoft Anypoint Exchange

New Security Checks

  • Added a check for applications performing certificate name validation to prevent reading invalid memory addresses (CVE-2024-6119)

Improvements

  • Updated the AuthVerificationService from .NET 6.0 to .NET 8.0

Fixes

  • Fixed an issue with missing links in imported files that were sent from the API Inventory to the agent
  • Fixed an issue where target names longer than 40 characters were not being truncated as expected on the Create New Target page
  • Fixed an issue where the “Download HTTP Request Logs” button triggered an error while a scan was in progress
  • Fixed an issue where user names containing the character “ä” could not be added
  • Fixed an issue with the scan data retention period for raw scan files that was not working as expected
  • Fixed missing scan completed notifications with report attachments
  • Fixed an issue where adding more than one name to a Notification’s Excluded Recipients would remove the other users from all other notifications
  • Fixed an issue where the verifier agent could not read or apply custom proxy settings from the appsettings.json file
  • Fixed an issue where uploading a .proto file caused a “No links found in the file” error
  • Fixed missing request/response details for some out-of-band vulnerabilities

v24.10.1 - 30 Oct 2024

This release includes new security checks, improvements, and bug fixes.

This update includes changes to the internal agents. The internal scan agent’s current version is 24.10.1. The internal authentication verifier agent’s current version is 24.10.1.

New Security Checks

Improvements

  • Changed the Mend integration to utilize an activation key so that the setup process is simpler

Fixes

  • Vulnerability profiles that are set as hidden will now still be reported in the scan reports of scans completed prior to the vulnerability being hidden
  • Fixed a bug in the editing of scan profiles with custom report policies
  • Resolved an issue in the exporting of team member data with all attributes selected
  • Resolved an issue with missing vulnerability profiles in custom report policies

v24.10.0 - 08 Oct 2024

This release includes a new feature, new security checks, improvements, and bug fixes.

This update includes changes to the internal agents. The internal scan agent’s current version is 24.10.0. The internal authentication verifier agent’s current version is 24.10.0.

New Features

  • API Security: Added integration with Azure API Management to fetch Swagger2 and OpenAPI3 specification files → Learn more

New Security Checks

Improvements

  • Database optimizations
  • Changed scanning without a duration limit to a customer support request-only option
  • Reporting improvements for the “Unknown Option Used In Referrer-Policy” vulnerability
  • Improved the behavior of the ‘Recent Scans’ button group on the global dashboard when using the mobile view

Fixes

  • Fixed a timeout bug in zero-configuration API discovery
  • Fixed some wording inconsistencies and other minor improvements to the user interface
  • Removal of sitemap data when a scan is canceled, failed, or aborted
  • Resolved an issue in the General Settings page configuration
  • Resolved an issue with user sessions not timing out in compliance with the specified configuration
  • Fixed a false positive issue with Boolean Based MongoDB Injection detection
  • Out-of-date version for Boolean Based MongoDB Injection is now reported correctly

v24.9.1 - 24 Sep 2024

This release includes a new feature, new security checks, improvements, and bug fixes.

This update includes changes to the internal agents. The internal scan agent’s current version is 24.9.1. The internal authentication verifier agent’s current version is 24.9.1.

New Feature

  • Administrators can now assign Agent Groups to Teams for greater control over agents and the teams that can use them. Contact our customer support team to activate this feature.

New Security Checks

  • Added XWiki version disclosure vulnerability and attack patterns.

Improvements

  • Added improvements to the Mend SAST integration.

  • Target to Project mapping is now available via API for the Mend SAST integration.

Fixes

  • Fixed the issue where tagging in the Discovery service would create a single-character tag when converted to a target.

  • Fixed an issue where the encryption process remained pending and incomplete after starting encryption key generation.

  • Fixed a bug in the API where ‘/api/1.0/issues/allissues’ always returned NULL in the History field.

  • The option to suspend all future scans is now available to all customers in Scans Control Settings.

  • Fixed the false negative issue related to Polyfill.io.

  • Fixed an issue related to creating a custom script for a web application using the OIDC method with a login pop-up.

  • Fixed the issue where the scan summary page did not time out according to the settings.

v24.9.0 - 10 Sep 2024

This release includes new security checks, improvements, and bug fixes.

This update includes changes to the internal agents. The internal scan agent’s current version is 24.9.0. The internal authentication verifier agent’s current version is 24.9.0.

New Security Checks

  • Adjusted the severity of SSLv3 and TLS 1.0 vulnerabilities to reflect their security risks
  • Added support for CSP frame-ancestors
  • Added detection for CVE-2024-6297, affecting several WordPress plugins

Improvements

  • Pre-request script now works in DOM as well
  • The Azure Extension now retries connections, preventing pipeline failures

Fixes

  • Remediated a high vulnerability issue on the Agent Dotnet dependency package
  • Fixed an issue that was preventing the selection of configuration items during ServiceNow integration setup
  • Fixed an issue with updating targets using the target group ID
  • Fixed an issue where the Auth Verifier heartbeat was showing an hour behind due to daylight saving time adjustments
  • Fixed an error that was occurring when editing Report Policies
  • Fixed an issue with a REST API endpoint returning alternating severity data for TLS 1.0 vulnerabilities
  • Resolved an issue with a pre-request script that was affecting crawling functionality

v24.8.2 - 29 Aug 2024

This release includes a new integration with Mend SAST.

New Feature

  • Integration with Mend SAST: display Mend SAST results alongside DAST results in Acunetix 360 so you can prioritize all your application security testing fixes in one list Learn more

v24.8.1 - 27 Aug 2024

This release includes new security checks and bug fixes.

This update includes changes to the internal and cloud agents. The internal scan agent’s current version is 24.8.1.

New Security Checks

  • Added detection for Jenkins Secret as a Sensitive Data Exposure

Fixes

  • Fixed the issue where the ServiceNow Integration fields were not loading while editing the integration
  • Fixed the issue where clicking the clone button in the Jira integration incorrectly redirected to the create new integration page
  • Fixed Chromium-related issues in the agent
  • Corrected the description of the “api/1.0/scans/test-scan-profile-credentials” endpoint
  • Fixed the error when selecting a custom time period in the Dashboard Date Range
  • Fixed the issue where temp folders could not be deleted and Chromium instances remained open when Puppeteer encountered an error
  • Fixed the display issue on the Scan Summary page
  • Fixed the false positive on detection of “Stack Trace Disclosure (Java)”
  • Fixed a scan authentication issue and reduced latency
  • Fixed the issue that was preventing the download of detailed PCI reports
  • Fixed an issue related to the Moment.js regex
  • Updated the OpenSSL configuration on the Cloud AMI
  • Fixed the disk space issue in the Invicti Common folder
  • Fixed the automatic syncing of issues with Jira integrations
  • Fixed the issue where scans were failing due to a TLS connection not being established
  • Fixed the OIDC authentication issue
  • Fixed the issue where the REST API endpoint returned HTTP 400 instead of HTTP 200 when sending custom values
  • Fixed the issue preventing proper login to the target URL

v24.8.0 - 13 Aug 2024

This release includes new security checks, improvements, and bug fixes.

This update includes changes to the internal and cloud agents. The internal scan agent’s current version is 24.8.0.

New Security Checks

  • Added a check for Authentication bypass in Fortra’s GoAnywhere MFT (CVE-2024-0204)
  • Added a check for Open SSH server RCE (CVE-2024-6387)
  • Added a check for cached pages that contain sensitive data (CWE-525)
  • Incorporated the reporting of sensitive information disclosures from Okta

Improvements

  • Added more links from the global dashboard widgets to the corresponding sections in the UI
  • Scheduled scans that repeatedly fail with the same result can now be automatically disabled
  • Unlinked API specs from the scan profile automatically unlink on the API Inventory page as well
  • Added the ability to navigate from the API operation vulnerability count in the API Inventory to a filtered list of vulnerabilities on the Issues page
  • Reverted the fix for a problem in the JWT Engine that was intended to resolve a false positive issue

Fixes

  • Fixed an issue that was causing intermittent errors in PCI reports
  • Fixed the ‘Bad Request’ error that was occurring in the vulnerability details of scan reports
  • Fixed an issue where the character ‘ñ’ was causing errors when updating or adding new users
  • Fixed the issue that was preventing deletion of unused scan policies
  • Fixed the issue where additional website vulnerabilities were being stored as target vulnerabilities
  • Fixed the missing tooltips for source errors on the API Sources page
  • Fixed the issue where the linked target URL was clickable even when the API specification was hidden
  • Resolved an issue that was causing an error when modifying the Settings in Acunetix 360

v24.7.4 - 08 Aug 2024

This release contains an update to the internal agents.

This update includes changes to the internal agents. The internal scan agent’s current version is 24.7.4. The internal authentication verifier agent’s current version is 24.7.4.

1 2 12