v24.5.240529155 - 30 May 2024
Release build 24.5.240529155 includes added hooking for some functions in the .NET Core IAST sensor, new security checks, improvements, and bug fixes.
New Features
- Adding hooking for the following functions in the .NET Core IAST sensor:
- System.Net.WebRequest
- System.AppDomain
- System.Type
- System.DirectoryServices
- MySql.Data.MySqlClient.MySqlDataAdapter
- SqlDataAdapter
New Security Checks
- GlobalProtect PAN-OS RCE (CVE-2024-3400)
- CrushFTP SSTI (CVE-2024-4040)
- PaperCut NG/MF Path Traversal (CVE-2023-39143)
- Fortinet Out-Of-Bound Memory Write RCE (CVE-2024-21762)
- Flowise Authentication Bypass (CVE-2024-31621)
- CData Jetty Path Traversal (CVE-2024-31848/CVE-2024-31849/CVE-2024-31850/CVE-2024-31851)
Improvements
- Further improvements in scanning of APIs
- Improved support for sites making use of HSTS
- Improved coverage of Single Page Applications (SPAs) using Next.js
- Improvement in SQL Injection checks
- Updated the list of known weak JWT secret keys
- Updated Chromium to 125.0.6422.76
Fixes
- Minor usability enhancements and fixes based on user feedback
- Fixed an issue that was causing a temporary hang of the LSR on certain sites
- Fixed an issue when OpenVAS network scan didn’t get executed properly