Changelogs

Acunetix Standard & Premium

RSS Feed

v23.11.231130164 - 04 Dec 2023

Release build 23.11.231130164 contains a fix for the SSO workflow.

Fixes

  • Fixed a bug in the SSO workflow

v23.11.231129195 - 30 Nov 2023

Release build 23.11.231129195 includes several improvements and bug fixes.

Improvements

  • Improvements to our Elmah security check
  • Improvements for Server Side Template Injection vulnerabilities (SSTI)
  • Additional logs for SSO

Fixes

  • Fixed a crash on Postman import
  • Client Certificate for target import fix

v23.11.231123131 - 23 Nov 2023

Release build 23.11.231123131 includes a fresh color scheme, new features and enhancements to the UI, as well as new security checks, improvements, and bug fixes.

New features

  • Every user can now choose which email notifications they receive by setting their individual preferences located in their User Profile
  • For Acunetix On-Premises customers, email server settings have been moved under the Settings menu
  • You can now open Acunetix on multiple tabs without needing to log in with every new tab you open
  • We’ve added CVSS 4.0 scores to some vulnerabilities — You’ll find the CVSS 4.0 score and vector displayed next to the old score (3.1/3.0/2.0, whichever is highest) in the UI and API
  • For Acunetix On-Demand customers, user management is now available under Settings > Users & Access. Here you’ll find the user list with some new filter options and a new way to create user accounts by generating an invitation link (the user specifies their own password instead of the administrator).

New security checks

Improvements

  • Email notifications now have the option to include a direct link for downloading PDF reports. Previously it was necessary to log in to Acunetix to download PDF reports.
  • Updated the Chromium Build to 119.0.6045.123/.124
  • Enhanced IAST .NET sensor detection capabilities
  • Improved location detection when using LSR
  • Improved scanner stability for select environments
  • Improvements to handling OpenAPI specifications
  • Multiple improvements to the SQL Injection vulnerability checks

Fixes

  • Fixed an issue that was causing Amazon WAF exports to fail
  • PDF reports now display information that was previously being cut off

v23.9.231020153 - 23 Oct 2023

Release build 23.9.231020153 includes new security checks and improvements to the SSL Engine.

New security checks

Improvements

  • Multiple improvements to the SSL Engine
  • Improvements to the detection of CVE-2023-27524
  • Improvements to the detection of SQL Injection vulnerabilities when using WAFs

v23.9.231013139 - 16 Oct 2023

Release build 23.9.231013139 includes a fix for XML Export and multiple improvements to the SSL Engine.

Fixes

  • Fix for XML Export

Improvements

  • Multiple improvements to the SSL Engine

v23.9.231005181 - 09 Oct 2023

Release build 23.9.231005181 includes several new security checks and improvements.

New security checks

Improvements

  • PHPSensor: Yii Framework logging improvements
  • .NET Sensor: Improvement to file list
  • Multiple improvements to SSL Checks

v23.9.230927167 - 28 Sep 2023

Release build 23.9.230927167 includes a significant update with the addition of critical severity as a new vulnerability classification, internal scanning agent support for proxy settings, and added detection of multiple SSL vulnerabilities.

New features

  • Added critical severity as a new vulnerability classification and reclassified select high vulnerabilities to critical severity – more information on the Acunetix blog
  • Added the ability to specify proxy settings for the Internal Scanning Agent

New security checks

  • Acunetix now detects the following SSL vulnerabilities:
  • Certificate signed using a weak signature algorithm
  • Revoked SSL certificate
  • Anonymous ciphers supported
  • SSL untrusted root certificate
  • Confirm validity of Certificate Authority (CA) signature

Improvements

  • Updated the user agent string to Chromium 117
  • Updated Chromium to 117.0.5938.63
  • Fixed misbehaving scrolling behavior in the LSR recorder screen
  • Improved detection of DOM-based XSS vulnerabilities
  • Moved license subscription details from the Profile section to Settings > Subscription
  • Improvements to DeepScan coverage
  • Improvements to the UI during scan configuration
  • Set client certificate import default format to PFX

Fixes

  • Engine/Open SSL: Fixed scanning sites that require connection with enabled legacy unsafe renegotiation
  • Minor UI navigation fixes
  • Fixed occasional crash on importing Postman files
  • Fixed false positive “ASP.NET expired session IDs are not regenerated“ when <sessionState> section of web.config is encrypted

v23.8.230918154 - 19 Sep 2023

Release build 23.8.230918154 includes an improvement for Acunetix On-Premises

Improvement

  • Increased logging for services (Acunetix On-Premises only)

v23.8.230905089 - 05 Sep 2023

Release build 23.8.230905089 includes the addition of critical severity as a new vulnerability level. We've also added many new security checks as well as improvements and bug fixes.

New features

  • Added critical severity as a new vulnerability level (for more information, check out our blog)

New security checks

  • Added security check for appwrite SSRF: CVE-2023-27159
  • Added security check for Metabase RCE: CVE-2023-38646
  • Updated WAF detection
  • Added security check for Ivanti EPMM Unauthenticated API Access: CVE-2023-35078
  • Added security check for MinIO Information Disclosure: CVE-2023-28432
  • Added security check for KeyCloak XSS: CVE-2021-20323
  • Added security check for Strapi Cognito provider Auth Bypass: CVE-2023-22893
  • Added security check for ServiceNow XSS: CVE-2022-38463
  • Added security check for SAP NetWeaver KW XSS: CVE-2021-42063
  • Added security check for XProber Information Disclosure
  • Added security check for SAP NetWeaver DI SSRF: CVE-2021-33690
  • Added security check for open Consul API detection
  • Updates to vulnerable WordPress plugins

Improvements

  • Upgraded to OpenSSL 3.1.2 (On-Premises only)
  • Improved LSR restrictions
  • Improved scanning so that repeated links with the same content are not detected
  • Improved scanning of recursive relative links
  • Crawling improvements by excluding repeated inexistent paths
  • When an issue is pushed to the issue tracker, the vulnerability detail shows the issue’s  URL for easier navigation
  • Updated the Software Composition Analysis (SCA) database
  • IAST – moved the .NET folder from ProgramData\Acunetix to ProgramData\Invicti folder. The Injector.exe (IAST .NET framework automatic installation tool) will force upgrade if an older version of IAST .NET Sensor is installed.

Fixes

  • Fixed a bug that was preventing starting a scan from Target Groups
  • Fixed a bug that was preventing System Admins from adding targets to Target Groups
1 3 4 5 26