Skip to content

Releases: zaproxy/zap-extensions

Windows WebDrivers version 120

15 Jan 09:24
7e2258c
Compare
Choose a tag to compare

Changed

  • Update ChromeDriver to 132.0.6834.83.

MacOS WebDrivers version 120

15 Jan 09:24
7e2258c
Compare
Choose a tag to compare

Changed

  • Update ChromeDriver to 132.0.6834.83.

Linux WebDrivers version 120

15 Jan 09:24
7e2258c
Compare
Choose a tag to compare

Changed

  • Update ChromeDriver to 132.0.6834.83.

Technology Detection version 21.44.0

15 Jan 10:11
bdec152
Compare
Choose a tag to compare

Changed

  • Updated with enthec upstream icon and pattern changes.
  • Update minimum ZAP version to 2.16.0.
  • Depend on Passive Scanner add-on (Issue 7959).
  • The scan rule no longer sets a CWE for alerts (Issue 8733).

Passive scanner rules (beta) version 42

15 Jan 10:11
bdec152
Compare
Choose a tag to compare

Changed

  • Update minimum ZAP version to 2.16.0.
  • Updated help with specific Category identifier for use with the Custom Payloads add-on for the "Dangerous JS Functions" rule.

Fixed

  • Fix typo in log message.
  • Fix Insufficient Site Isolation scan rule check that filters responses based on whether a response is a success or not.

Changed

  • Maintenance changes.

Custom Payloads version 0.14.0

15 Jan 10:11
bdec152
Compare
Choose a tag to compare

Changed

  • Promoted to Release status.
  • Update minimum ZAP version to 2.16.0.
  • Maintenance changes.
  • The superfluous/unused ID element of the custom payloads has been removed from the GUI and config.
  • Now depends on the Common Library add-on.

Added

  • Add help button to Options panel and add further detailed Help content.

Fixed

  • The add-on will no longer attempt to save or load Payloads for which there is no Category.
  • Ensure file is selected, exists, and is readable when attempting to import multiple payloads.

Active scanner rules (beta) version 57

15 Jan 10:11
bdec152
Compare
Choose a tag to compare

Changed

  • Update minimum ZAP version to 2.16.0.
  • The following scan rules now use more specific CWE IDs:
    • Proxy Disclosure (Issue 8713)
    • Possible Username Enumeration (Issue 8715)
  • Remove double dot in skipped message of scan rules that use the Active Scan OAST service.

Fixed

  • Address exception when scanning a message without path with Possible Username Enumeration scan rule.
  • The WSTG alert tags on the HTTP Only Site scan rule.

Added

  • Standardized Scan Policy related alert tags on various rules.

Zest - Graphical Security Scripting Language version 48.0.0

10 Jan 10:40
b4bd534
Compare
Choose a tag to compare

Added

  • Allow other add-ons to create a Zest script from a list of messages.

Changed

  • Update minimum ZAP version to 2.16.0.
  • Use Semantic Version.
  • Maintenance changes.
  • Depend on Passive Scanner add-on (Issue 7959).

WebSockets version 32

10 Jan 10:40
b4bd534
Compare
Choose a tag to compare

Changed

  • Update minimum ZAP version to 2.16.0.

Fixed

  • Correct location/function of New Context context menu item.

Windows WebDrivers version 119

10 Jan 10:40
b4bd534
Compare
Choose a tag to compare

Changed

  • Update minimum ZAP version to 2.16.0.