Changelogs

Acunetix Standard & Premium

RSS Feed

v14.5.211021117 - 21 Oct 2021

Version 14 build 14.5.211021117 for Windows, Linux and macOS – 21st October 2021

Fixes

  • Fixed crash when processing swagger2 file with non-existent references

v14.5.211008143 - 11 Oct 2021

Version 14 build 14.5.211008143 for Windows, Linux and macOS – 11th October 2021

New Features

New Vulnerability Checks

Updates

  • Export to AWS WAF is now available in all pages which allow WAF Export
  • Updated Pre-request scripts, making it easier to update session header value
  • Updated the detection of WAFs to support new WAFs
  • Increased the detection of development files
  • Improved the JavaScript Library Audit checks

Fixes

  • Fixed issue in Paros import
  • Fixed issue in scanner causing False Negatives when processing specific pages
  • Fixed issue in AWS WAF Export
  • Fixed issue in PHP Sensor not being detected when used in a large site with many files
  • Fixed issue causing pre-request scripts not to be loaded by scanner
  • Fixed 3 issues in Postman imports
  • Fixed False Negative in Django Debug Mode vulnerability check
  • Fixed issue causing high response times in UI caused by large quantity of Targets configured
  • Fixed false positive in “User credentials are sent in clear text” check

v14.4.210913167 - 14 Sep 2021

Version 14 build 14.4.210913167 for Windows, Linux and macOS – 14th September 2021

New vulnerability checks

Updates

  • Updated CORS Origin Validation check

v14.4.210831180 - 01 Sep 2021

Version 14 build 14.4.210831180 for Windows, Linux and macOS – 1st September 2021

Fixes

  • Fixed: Error when adding new Targets
  • Fixed: Scanner crash when using a Postman import file

v14.4.210826124 - 26 Aug 2021

Version 14 build 14.4.210826124 for Windows, Linux and macOS – 26th August 2021

New Vulnerability checks

Updates

  • “AllOf” tag is now handled for Swagger2 schemas
  • Improved handling of import files for sub-domains and allowed hosts

Fixes

  • Fixed: Inexistant paths identified by WordPress checks
  • Fixed: Scanner crashing on specific content

v14.4.210816098 - 16 Aug 2021

Version 14 build 14.4.210816098 for Windows, Linux and macOS – 16th August 2021

New Features

  • Pre-request script support
  • New Log Data Retention options

New Vulnerability Checks

Updates

  • Max items shown per page can now be configured
  • Updated Deepscan to process hashes in URLs
  • Updated Chromium to v92.0.4512.0
  • Updated CSV export to include text only details
  • JavaScript Library Audit now supports merged JavaScript files
  • Added support for dev tools in standalone LSR
  • Multiple UI updates
  • Multiple LSR updates
  • Target knowledgebase will now be reset when Target settings are changed
  • Updated Selenium import to support selectFrame
  • Updated OWASP Top 10 report to include CVSS score
  • Updated Compliance report to include CWE
  • Added option to enable debuglogs for all Targets
  • Optimisations to the Java and Node.js AcuSensors
  • Improved support for Hapi framework in Node.js AcuSensor
  • Add support for find-my-way HTTP router in Node.js AcuSensor
  • Improved ionCube Loader-wizard information disclosure check
  • Improved cache poisoning DOS checks
  • Improved detection of Apache Struts2 Remote Command Execution (S2-052)
  • Improved detection of Directory Traversal vulnerabilities
  • Added option to skip testing of login form configured for the Target
  • Improved handling of Custom 404 pages

Fixes

  • Fixed multiple crashes in the scanner
  • Fixed issue causing some requests to be done to restricted links
  • Addressed multiple Deepscan issues
  • Paused scans can now be Aborted
  • Fixed XPath Injection false positive
  • Fixed Bitrix Open Redirect false positive
  • Fixed Spring Boot Actuator false negative
  • Fixed issue in .NET Sensor Manager not showing buttons on lower resolutions

v14.3.210628104 - 28 Jun 2021

Version 14 build 14.3.210628104 for Windows, Linux and macOS – 28th June 2021

Updates

  • Target Knowledgebase will be reset when Target Settings are changed
  • Updated SSL/TLS Certificate expiry threshold notification from 30 days to 60 days

Fixes

  • Fixed: OWASP compliance report template to not be available in some Editions
  • Fixed: Some scripts where not observing Excluded paths configured in Target settings

v14.3.210615184 - 17 Jun 2021

Version 14 build 14.3.210615184 for Windows, Linux and macOS – 17th June 2021

New Features

  • New SCA (Software Composition Analysis) for PHP, JAVA, Node.js and .NET web applications. Acunetix will report vulnerable libraries used by the web application when AcuSensor is used

New Vulnerability Checks

Updates

  • Updated .NET AcuSensor
  • .NET AcuSensor can be now deployed from CLI
  • User is notified when imported URLs are out of scope
  • Scan events are not shown in json any more
  • New column for Continuous Scanning in the Targets page
  • New filter in Targets page to easily identify Targets with debug enabled
  • Vulnerabilities page shows if the vulnerability was detected by a web or network scan
  • Merged Add Target and Add Targets options in UI
  • Custom Field, labels and tags can be configured for Issue Trackers
  • Platform Admin can now unlock locked accounts
  • New column in CSV export showing details in text only
  • Updated the way that AcuSensor token can be updated in the Target Settings
  • PCI DSS compliance report updated to PCI DSS 3.2.1
  • Compliance Reports updated to make use of the Comprehensive report template
  • Browser Dev tools can be used when LSR is started from CLI
  • Updated XFO check
  • Multiple UI updates
  • Improved false positive detection of out of band RCE and argument injection vulnerabilities
  • Multiple updates to the Postman import implementation
  • Updated JavaScript Library Audit to support merged JavaScript files

Fixes

  • HSTS has been enabled for the AcuSensor bridge
  • Latest Alerts section of Scan results was not updated with AcuMonitor (OOB) vulnerabilities)
  • The Fragments was not clickable in the site structure
  • HSTS Best Practices was sometimes being reported multiple times
  • Fixed HSTS false negative
  • Fixed issue in the detection of Django 3 weak secret
  • Fixed issue causing GitHub labels not to be updated when changing Github issue Tracker Project
  • Fixed encoding issue in Node.js AcuSensor
  • Fixed issue causing corruption of Target knowledgebase
  • Fixed DeepScan timeout when processing Prototype JavaScript library
  • Fixed issue causing outdated JavaScript libraries check not to report external libraries
  • Fixed issue in Oauth password credentials grant

v14.2.210505179 - 06 May 2021

Version 14 build 14.2.210505179 for Windows, Linux and macOS – 6th May 2021

Fixes

  • Fixed validation errors when sorting vulnerabilities by Issue ID
  • Fixed issue causing Node.js sensor to fail to start on Node v6
  • Fixed issue causing some operations to be listed multiple times in Scan Statistics
1 8 9 10 27