Release Notes

Acunetix Standard & Premium

RSS Feed

v24.1.240111130 - 11 Jan 2024

Release build 24.1.240111130 includes a new Java 17 IAST sensor, an update for Docker and Linux, as well as many new security checks. Along with a new navigational experience, we've also made some more improvements and bug fixes.

New features

  • The Java IAST sensor has been updated to support Java 17 and removes the requirement for AspectJWeaver
  • Changes to the mechanism that manages services for Acunetix On-Premises for Docker and Linux (Customers using Acunetix On-Premises for Docker or Linux need to manually update to version 24.1)

New security checks

Improvements

  • Updated .NET (core) IAST sensor to hook new functions
  • The scanner will now properly report when the protocol (http/https) is changed at the start of the scan
  • Increased the size limit to 10kB for supported Client Certificates for authenticated scans
  • Updated to Chromium 119.0.6045.199/200
  • Users can opt-in to receive a direct download link instead of a PDF report attachment (On-Prem only)
  • Improved crawling of Single Page Applications (SPA) that are using React
  • Improved crawling of Single Page Applications (SPA) that are using the Angular Framework
  • Improved crawling of Single Page Applications (SPA) that are using the Vue.js Framework
  • New User Profile design
  • A refreshed UI with a new navigational experience

Fixes

  • Fixed an issue that was causing some vulnerabilities not to be exported to Amazon AWS WAF
  • Fixed a Deepscan and LSR issue caused when a page overrides the standard window.* methods
  • Notifications about scans that require manual intervention are now correctly displayed wherever the user is located (On-Prem only)
  • Fixed a number of scanner crashes

v23.11.231130164 - 04 Dec 2023

Release build 23.11.231130164 contains a fix for the SSO workflow.

Fixes

  • Fixed a bug in the SSO workflow

v23.11.231129195 - 30 Nov 2023

Release build 23.11.231129195 includes several improvements and bug fixes.

Improvements

  • Improvements to our Elmah security check
  • Improvements for Server Side Template Injection vulnerabilities (SSTI)
  • Additional logs for SSO

Fixes

  • Fixed a crash on Postman import
  • Client Certificate for target import fix

v23.11.231123131 - 23 Nov 2023

Release build 23.11.231123131 includes a fresh color scheme, new features and enhancements to the UI, as well as new security checks, improvements, and bug fixes.

New features

  • Every user can now choose which email notifications they receive by setting their individual preferences located in their User Profile
  • For Acunetix On-Premises customers, email server settings have been moved under the Settings menu
  • You can now open Acunetix on multiple tabs without needing to log in with every new tab you open
  • We’ve added CVSS 4.0 scores to some vulnerabilities — You’ll find the CVSS 4.0 score and vector displayed next to the old score (3.1/3.0/2.0, whichever is highest) in the UI and API
  • For Acunetix On-Demand customers, user management is now available under Settings > Users & Access. Here you’ll find the user list with some new filter options and a new way to create user accounts by generating an invitation link (the user specifies their own password instead of the administrator).

New security checks

Improvements

  • Email notifications now have the option to include a direct link for downloading PDF reports. Previously it was necessary to log in to Acunetix to download PDF reports.
  • Updated the Chromium Build to 119.0.6045.123/.124
  • Enhanced IAST .NET sensor detection capabilities
  • Improved location detection when using LSR
  • Improved scanner stability for select environments
  • Improvements to handling OpenAPI specifications
  • Multiple improvements to the SQL Injection vulnerability checks

Fixes

  • Fixed an issue that was causing Amazon WAF exports to fail
  • PDF reports now display information that was previously being cut off

v23.9.231020153 - 23 Oct 2023

Release build 23.9.231020153 includes new security checks and improvements to the SSL Engine.

New security checks

Improvements

  • Multiple improvements to the SSL Engine
  • Improvements to the detection of CVE-2023-27524
  • Improvements to the detection of SQL Injection vulnerabilities when using WAFs

v23.9.231013139 - 16 Oct 2023

Release build 23.9.231013139 includes a fix for XML Export and multiple improvements to the SSL Engine.

Fixes

  • Fix for XML Export

Improvements

  • Multiple improvements to the SSL Engine

v23.9.231005181 - 09 Oct 2023

Release build 23.9.231005181 includes several new security checks and improvements.

New security checks

Improvements

  • PHPSensor: Yii Framework logging improvements
  • .NET Sensor: Improvement to file list
  • Multiple improvements to SSL Checks

v23.9.230927167 - 28 Sep 2023

Release build 23.9.230927167 includes a significant update with the addition of critical severity as a new vulnerability classification, internal scanning agent support for proxy settings, and added detection of multiple SSL vulnerabilities.

New features

  • Added critical severity as a new vulnerability classification and reclassified select high vulnerabilities to critical severity – more information on the Acunetix blog
  • Added the ability to specify proxy settings for the Internal Scanning Agent

New security checks

  • Acunetix now detects the following SSL vulnerabilities:
  • Certificate signed using a weak signature algorithm
  • Revoked SSL certificate
  • Anonymous ciphers supported
  • SSL untrusted root certificate
  • Confirm validity of Certificate Authority (CA) signature

Improvements

  • Updated the user agent string to Chromium 117
  • Updated Chromium to 117.0.5938.63
  • Fixed misbehaving scrolling behavior in the LSR recorder screen
  • Improved detection of DOM-based XSS vulnerabilities
  • Moved license subscription details from the Profile section to Settings > Subscription
  • Improvements to DeepScan coverage
  • Improvements to the UI during scan configuration
  • Set client certificate import default format to PFX

Fixes

  • Engine/Open SSL: Fixed scanning sites that require connection with enabled legacy unsafe renegotiation
  • Minor UI navigation fixes
  • Fixed occasional crash on importing Postman files
  • Fixed false positive “ASP.NET expired session IDs are not regenerated“ when <sessionState> section of web.config is encrypted
1 4 5 6 28