v15.1.221109177 - 10 Nov 2022
Version 15 build 15.1.221109177 for Windows and Linux – 10 November 2022
New features
- New navigation menu for a better user experience.
- Notification updates are shown for the last 30 days
New vulnerability checks
- New check for Swagger UI DOM XSS vulnerability.
- New test for Fortinet Authentication bypass on the administrative interface (CVE-2022-40684).
- New test for Insecure usage of Version 1 UUID/GUID.
- New test for Text4shell: Apache Commons Text RCE via insecure interpolation (CVE-2022-42889).
- New test for OpenSSL X.509 Email Address Buffer Overflows (CVE-2022-3786).
- Updated test for Open Monitoring Interfaces.
- Updated the software composition analysis database.
- Updated the WordPress plugin vulnerabilities.
Updates
- Updated the embedded Chromium browser to v107.0.5304.87/88.
- Updated how scans reaching max scan time are displayed in UI.
- Updated Issue Tracker UI to accept internal URLs.
- Improved Log4J checks to reduce false positives.
Fixes
- Fixed the issue causing the IAST bridge to fail to send responses to the sensor when large packets are received from the sensor.
- Added loopback routes that returned ‘undefined’ as an HTTP method.
- Added the keep connection alive message between AcuSensor and the web application scanner to keep the connection alive.