Changelogs

Acunetix Standard & Premium

RSS Feed

v14.6.211215172 - 16 Dec 2021

Version 14 build 14.6.211215172 for Windows, Linux and macOS – 16th December 2021

New Vulnerability Checks

  • Apache Log4j RCE vulnerability check updated to detect the vulnerability in web server exceptions
  • Apache Log4j RCE vulnerability check updated to execute on various HTTP Headers

Updates

  • Updated the scanner to test custom headers used by the web application

v14.6.211213163 - 13 Dec 2021

Version 14 build 14.6.211213163 for Windows, Linux and macOS – 13th December 2021

New Vulnerability Checks

v14.6.211207099 - 07 Dec 2021

Version 14 build 14.6.211207099 for Windows, Linux and macOS – 7th December 2021

New Features

  • Scanner supports detecting HTTP/2 vulnerabilities

New Vulnerability Checks

Updates

  • Improved handling of Laravel CSRF tokens
  • Added possibility to restrict scanning a Target using the Main Installation’s scanning engine
  • Added ability to configure blocking of requests to Ad services
  • Multiple UI updates
  • Multiple DeepScan updates
  • Multiple updates to the PHP AcuSensor

Fixes

  • Fixed: SQLi false negative caused when AcuSensor is installed
  • Fixed: Incremental scans not starting when scheduled via Jenkins plugin
  • Fixed: 2 issues in .NET sensor injector CLI
  • Fixed: Node.js sensor not working on https sites
  • Fixed: Not all paths are importing from specific Burp state file
  • Fixed: Scanner crashes when parsing specific GraphQL and Swagger 2 files
  • Fixed: Specific excluded paths can cause the scanner to hang
  • Fixed: multiple scanner hangs
  • Fixed: Race condition between LSR and BLR
  • Fixed: Imported urls ignored when site redirects from http to https
  • Fixed: Incorrect permissions for some Acunetix files / folders on Linux / Mac

v14.5.211115146 - 16 Nov 2021

Version 14 build 14.5.211115146 for Windows, Linux and macOS – 16th November 2021

New Features

  • New OWASP Top 10 2021 compliance report
  • JAVA AcuSensor now supports JDK 11

New Vulnerability Checks

Fixes

  • Fixed issue causing hang in scanner
  • Fixed issue causing some vulnerabilities not to be detected when AcuSensor is enabled and not installed on the web application

v14.5.211109105 - 09 Nov 2021

Version 14 build 14.5.211109105 for Windows, Linux and macOS – 9th November 2021

New Vulnerability Checks

Fixes

  • Fixed issue in .NET AcuSensor CLI parameter used to list the web sites in IIS
  • Fixed issue in Clickjacking: CSP frame-ancestors missing vulnerability check
  • Fixed false positive in Сockpit CMS reset password NoSQLi

v14.5.211026108 - 26 Oct 2021

Version 14 build 14.5.211026108 for Windows, Linux and macOS – 26th October 2021

Updates

  • Removed message to “Press any key to continue” when installing .NET AcuSensor from CLI. This was hindering the automatic installation of the .NET sensor

Fixes

  • Fixed issue causing scans to fail when site redirets from http to https
  • Fixed issue causing incremental scans initiated from Jenkins plugin not to start

v14.5.211021117 - 21 Oct 2021

Version 14 build 14.5.211021117 for Windows, Linux and macOS – 21st October 2021

Fixes

  • Fixed crash when processing swagger2 file with non-existent references

v14.5.211008143 - 11 Oct 2021

Version 14 build 14.5.211008143 for Windows, Linux and macOS – 11th October 2021

New Features

New Vulnerability Checks

Updates

  • Export to AWS WAF is now available in all pages which allow WAF Export
  • Updated Pre-request scripts, making it easier to update session header value
  • Updated the detection of WAFs to support new WAFs
  • Increased the detection of development files
  • Improved the JavaScript Library Audit checks

Fixes

  • Fixed issue in Paros import
  • Fixed issue in scanner causing False Negatives when processing specific pages
  • Fixed issue in AWS WAF Export
  • Fixed issue in PHP Sensor not being detected when used in a large site with many files
  • Fixed issue causing pre-request scripts not to be loaded by scanner
  • Fixed 3 issues in Postman imports
  • Fixed False Negative in Django Debug Mode vulnerability check
  • Fixed issue causing high response times in UI caused by large quantity of Targets configured
  • Fixed false positive in “User credentials are sent in clear text” check

v14.4.210913167 - 14 Sep 2021

Version 14 build 14.4.210913167 for Windows, Linux and macOS – 14th September 2021

New vulnerability checks

Updates

  • Updated CORS Origin Validation check
1 7 8 9 26