artifacthub helm/securecodebox/persistence-defectdojo 3.15.2
v3.15.2

latest releases: 4.8.0, 4.7.0, 4.6.1...
21 months ago

Changes

This release is a security release and is highly recommended for all users of the zap-advanced ScanType.

Big thanks to @patrykzzz for pointing out the issue and providing a fix 🙌

GitHub commits since tagged version GitHub Repo stars Twitter URL

🔒 Security

When using the JSON authentication method in the ZAP Advanced scanner the python script configuring the ZAP was logging the credentials (username & password) used. The vulnerability is present in our secureCodeBox scripts, not in ZAP itself. Only the zap-advanced ScanType is affected, zap-baseline-scan, zap-api-scanand zap-full-scan are not affected.

Distribution

Artifact HUB
Docker Hub

Contributors

Thanks to all our contributors supporting this project 🤗
@patrykzzz

Don't miss a new persistence-defectdojo release

NewReleases is sending notifications on new releases.