Changelogs

Acunetix 360 On-Demand

RSS Feed

17 Jan 2023

This release includes new features, improvements, and fixes. We added support for OpenShift and a control center to suspend scans in case. We improved ServiceNow and Jira integrations. We also fixed some bugs.

This update includes changes to the internal agents. The internal scan agent’s current version is 2.0.2.159. The internal authentication verifier agent’s current version is 2.0.2.159.

New features

  • Added the ability to run a scanner agent for the OpenShift environment.
  • Added a scan control center to suspend all scans, and pause and resume all scans when needed.
  • Added control for login and logout during vulnerability retest.

Improvements

  • Improved the Invicti web application performance.
  • Improved the ServiceNow Incident Management integration.
  • Improved the detection of whether the Jira instance is on the cloud or on-premises.
  • Improved the Jira integration to add the Affected Versions as an option.
  • [Early Release] Change the Second Level Domain option on the Discovery Service to disabled by default.
  • Change the icon of the vulnerability list for website groups on the Reporting page.
  • Added the keep connection alive message between Invicti Shark (IAST) and the web application scanner to keep the connection alive.
  • Improved the vulnerability report in which any credit card information is masked.
  • Added the Authentication Verifier Service’s IP address to the setting to prevent it from being affected by the IP Restrictions.
  • Improved the agent’s configuration file to specify a folder where the agent’s scan data is to be saved.
  • Improved the API endpoint to create team members and update their information.
  • Added the last revived date parameter to the All Issues API endpoint.
  • Improved the maximum scan duration detection.
  • Updated the TeamCity plugin that requires the Server URL and Domain URL to be the same.
  • Added the GUID control before getting the integration id to prevent any issue in the flow.
  • Improved the scanning of Burp files that are without XML extensions.
  • Increased the time out for the cloud PDF converter to prevent timeout-related errors.

Fixes

  • Fixed case sensitivity when checking HTTP headers for JWT.
  • Fixed missing CSP 3 Directive.
  • Removed the redundant semicolon on the scan pages.
  • Fixed an issue that prevented the new website group from appearing on the Manage Groups page immediately.
  • Fixed a bug that prevents the scanner from attacking to login and logout pages.
  • Fixed the policies loading issue on the General Settings page.
  • Fixed the user interface issue to reflect the agent information on the Installed Framework accurately.
  • Fixed the inconsistent risk level on the generated reports. 
  • Fixed the IPv6 registered website resolution issue thrown before scanning.
  • Fixed the bug of excluding addressed issues in reports generated via Azure Pipeline Extension.
  • Fixed the synchronization issue for the Discovery Service.
  • Fixed the bug that throws a null reference exception at the authentication.
  • Fixed a bug that prevents the scanner from attacking to login and logout pages.
  • Fixed an issue that overrode TLS settings available in the scan policy when the Ignore SSL Certificate Errors is set to True in the Appsetting.json file.
  • Fixed the bug in which OAuth2 settings were not transferred properly from the web application to the agent.
  • Fixed the bug that threw an error when exporting a report.
  • Fixed null reference error during SCIM User creation.

21 Dec 2022

This release includes improvements and fixes. We fixed an agent stuck issue and TLS setting.

This update includes changes to the internal agents. The internal scan agent’s current version is 2.0.2.158. The internal authentication verifier agent’s current version is 2.0.2.158.

IMPROVEMENTS

  • Added auto responder for images to escape the onerror issue.

FIXES

  • Fixed the agent stuck issue when the scan timeout is detected.
  • Fixed an issue that overrode TLS settings available in the scan policy when the Ignore SSL Certificate Errors is set to True in the Appsetting.json file.

13 Dec 2022

This release includes a hotfix for the Discovery Service.

Fixes

  • Fixed the attribute issue that prevented the Discovery Service from running the discovery properly.

07 Dec 2022

This release includes new features, improvements, and fixes. We added the feature to generate a report on website groups. We improved the ServiceNow Incident Management and Jira integration. We also fixed some bugs.

This update includes changes to the internal agents. The internal scan agent’s current version is 2.0.2.157. The internal authentication verifier agent’s current version is 2.0.2.157.

New Features

Improvements

  • Improved the ServiceNow Incident Management.
  • Improved the Jira integration to export a vulnerability’s details to the Jira ticket.
  • Improved the SSO to inform users about the expired SAML certificate.
  • Added an explanation for the failed requests error.
  • Added name variable support for Passive and Singular Custom Security Checks.

Fixes

  • Fixed the Business Logic Recorder issue that prevents login when there is a custom script for the form authentication.
  • Improved the creation of websites via the Discovery Service to include the port numbers and the URL.
  • Fixed a bug that displayed vulnerabilities without their id on the website and global dashboard page.
  • Fixed WSDL parse issue for non-defined object types.
  • Fixed the null reference exception on HTTP Requester.
  • Fixed the internal agent update issue that is stuck in the updating process.

Removed

  • Removed the .NET installation requirement for internal agents.

22 Nov 2022

This release includes improvements and fixes. We improved the website dashboard performance. Also, we fixed some bugs.

Improvements

  • [Early Access] Improved the AWS connection to scan only the top 10 most popular web framework ports from the AWS Security Group.
  • Improved the website dashboard performance.
  • Improved the discovered website page to customize columns based on your needs.
  • Added the attack option for Cross-site Request Forgery (CSRF).
  • Added the required tooltip for the Value field of the Kafka integration.

Fixes

  • Fixed the bug in sending issues to Mattermost.
  • Fixed the Slack integration issue that failed to send notifications.
  • Fixed the inconsistent discovered website result by handling null values.
  • Fixed a bug that prevented the PCI scan from running ever again if any previous PCI scan failed to start.

08 Nov 2022

This update includes changes to the internal agents. The internal scan agent’s current version is 2.0.2.156. The internal authentication verifier agent’s current version is 2.0.2.156. New security check Added the Text4Shell (CVE-2022-42889) check. Improvements Updated the docker scanner agent. Added an active scan check before...

This update includes changes to the internal agents. The internal scan agent’s current version is 2.0.2.156. The internal authentication verifier agent’s current version is 2.0.2.156.

New security check

Improvements

  • Updated the docker scanner agent.
  • Added an active scan check before deleting a scan profile related to that active scan.
  • Improved the importing link to parse the complex example value for RAML.

Fixes

  • Fixed the issue in which the authentication verifier agent is not listed after the time zone is changed.
  • Improved the authentication verifier configuration file to support using the plus (+) for space encoding.
  • Improved the log for the knowledge base report.
  • Fixed the mistaken information on the retestable vulnerabilities.
  • Fixed the fix calculation bug in the Issues API endpoint that occurred when scan(s) are deleted.
  • Fixed the issue that deleted the customization folder in the agent’s folder after the update.
  • Fixed the bug that displayed different method icons on the technical report page.

25 Oct 2022

Improvements [Early Access] Added information message to the AWS Discovery Connection that the results may take some time to appear on the discovered websites page. Added a name validation for adding a new member’s name and editing a member’s name. Added an option to export...

Improvements

  • [Early Access] Added information message to the AWS Discovery Connection that the results may take some time to appear on the discovered websites page.
  • Added a name validation for adding a new member’s name and editing a member’s name.
  • Added an option to export the PCI DSS scan report even if the scan fails.
  • Improved the global dashboard performance.

Fixes

  • Fixed the issue that showed the wrong country flags for country phone codes.
  • Fixed the product name in lowercase for those customers using Turkish Windows OS.

14 Oct 2022

Acunetix 360 On-Demand Update - 14 October 2022

This update includes changes to the internal agents. The internal scan agent’s current version is 2.0.2.155. The internal authentication verifier agent’s current version is 2.0.2.155.

FIXES

  • Fixed the comma issue that appeared when the scan is launched with the Header Authentication.
  • Fixed the internal agent issue in which the scan is stuck after the scan is canceled.

 


13 Oct 2022

Acunetix 360 On-Demand Update - 13 October 2022

This update includes changes to the internal agents. The internal scan agent’s current version is 2.0.2.154. The internal authentication verifier agent’s current version is 2.0.2.154.

NEW FEATURES

  • Added auto-GraphQL attack after endpoint is detected.

NEW SECURITY CHECKS

  • Added MongoDB Time-based (Blind) Injection.
  • Added SQLite Boolean SQL Injection.
  • Added MongoDB Error-based Injection.

IMPROVEMENTS

  • Improved the Trend Matrix Report exporting to include the severity information as well.
  • Improved the HashiCorp integration to authenticate with user tokens, too.
  • Updated Vulnerability Detection Logic in the JWT engine.
  • Improved the GraphQL scanning to include the separated comment lines in GraphQL files.
  • Improved the Authentication Verifier Agent to work with self-signed SSL.
  • Improved the Azure Pipeline Extension to generate a scan report on the release pipeline.
  • Updated Liferay Portal signature & added a mapping for version conversion.

FIXES

  • Fixed a bug that corrupts the header authentication credentials after updating the scheduled scan.
  • Fixed the status information showing different data on the Discovered Webpages page.
  • Fixed the Docker Agent build fail because of the compiler package.
  • Fixed the Total Elapsed and Average Time values displaying 00:00:00 on the Scan Performance tab of the Technical Report.
  • Fixed the time values displaying 00:00:00 on the Crawling Performance node of the Technical Report.
  • Fixed the Authentication Verifier Agent’s time zone bug.
  • Fixed the bug that duplicates the login page when users try to revalidate the login form.
  • Fixed the bug on the user interface of ServiceNow Incident Management integration that caused issues with the On Hold status.
  • Fixed the bug on the user interface of ServiceNow Incident Management integration that caused issues with the Closed status.
  • Fixed the Single Sign-on – encryption certification issue.
  • Fixed the web security issue for the origin header problem.
  • Fixed the sitemap bug that caused missing information when imported.
  • Fixed the bug that threw an error, as HTTP Requester deletes the whole body part of the request which contains the login credentials.
  • Fixed highlighting CSP Directives in different header issues.
  • Fixed duplicate bearer tokens for some requests.
  • Fixed an issue that resulted in false positive Cross-site Scripting (DOM-based).
  • Fixed the bug that shows the previous version of VDB.
  • Fixed parseable false attack patterns place.

1 5 6 7 12