Release Notes - 1.5
-
1.5.5-funcrel
1.5.5-funcrel
Updates embedded libraries. Updates internal evaluation engine leading to an overall enhancement of the accuracy of several security rules. 📝 44211 -
1.5.4-funcrel
1.5.4-funcrel
Updated embedded libraries. -
1.5.3-funcrel
1.5.3-funcrel
THIS VERSION WAS RELEASED BY ACCIDENT AND HAS BEEN DELETED FROM EXTEND. -
1.5.2-funcrel
1.5.2-funcrel
Fixes an error generating the message in the analysis log: “AttributeError: ‘MemberAccess’ object has no attribute ‘get_name’”. Fix missing violation for rule “Avoid using XPathFactory without restriction of XML External Entity Reference (XXE)” when setting the initial value of an Xpath field. 💎 1039038 Fix false positive for rule “Avoid using the Non-Serializable Object Stored in Session” when Object has an inner class. 💎 1039068 Fix missing violation for rule “Avoid creating cookie without setting httpOnly option (JEE)” when calling HttpServletResponse.addHeader(). 💎 1039026 Fix missing violation for rule “Avoid using unsecured cookie (JEE)” when calling HttpServletResponse.addHeader(). 💎 1039024 1.5.1-funcrel
1.5.1-funcrel
Fix false positive for rule “Avoid using TransformerFactory without restriction of XML External Entity Reference (XXE)”. 📝 48146 Fixed the “RuntimeError: property is not registered for given object type” when analyzing java classes that have initialization blocks. Fix error “AttributeError: ‘Object’ object has no attribute ‘get_inherited_types’” when analyzing a java.util.Map for rule “Avoid using the Non-Serializable Object Stored in Session”. 💎 1039068 Fix mixing violation of rule “Avoid using XPathExpression without a configurable secure parser (XXE)” for instances created with a call to XPathFactory.newDefaultInstance(). 💎 1039094 Fix mixing violation of rule “Avoid using XMLInputFactory without restriction of XML External Entity Reference (XXE)” for instances created with a call to XMLInputFactory.newFactory(). 💎 1039040 1.5.0-funcrel
1.5.0-funcrel
Fixed missing violations for the rule “Avoid using the Non-Serializable Object Stored in Session”. 💎 1039068 NEW Ensure secure option is enabled when creating session (JEE) 💎 1039098 NEW Ensure httpOnly option is enabled when creating session (JEE) 💎 1039096 Changed the specifications of rule “Avoid creating cookie without setting httpOnly option (JEE)”. The “web.xml” configuration file is no longer a remediation for this rule. 💎 1039026 Changed the specifications of rule “Avoid using unsecured cookie (JEE)”. The “web.xml” configuration file is no longer a remediation for this rule. 💎 1039024 1.5.0-beta3
1.5.0-beta3
Fixes false negative for the rule 1039062: “Always implement readObject() to prevent untrusted deserialization when loading from ObjectInputStream”. 📝 44850 Fixes false negative for the rule “Avoid using DocumentBuilder without restriction of XML External Entity Reference (XXE)” when calling method createXMLEventReader(). 💎 1039040 Fixes false positive for the rule: “Avoid using DocumentBuilder without restriction of XML External Entity Reference (XXE)” when using setEntityResolver(). 💎 1039034 Fixes false positive for the rule: “Avoid using DocumentBuilder without restriction of XML External Entity Reference (XXE)” when using setEntityResolver(). Bookmark was moved to the call to parse() method. 💎 1039032 NEW Avoid using XPathExpression without a configurable secure parser (XXE) 💎 1039094 NEW Avoid using JAXB Unmarshaller without a configurable secure parser (XXE) 💎 1039092 NEW Avoid using java.beans.XMLDecoder (XXE) 💎 1039090 NEW Avoid using Validator without restriction of XML External Entity Reference (XXE) 💎 1039088 NEW Avoid using DOMParser without restriction of XML External Entity Reference (XXE). 💎 1039086 1.5.0-beta2
1.5.0-beta2
NEW Avoid using SAXBuilder without restriction of XML External Entity Reference (XXE) 💎 1039084 NEW Avoid using SAXTransformerFactory without restriction of XML External Entity Reference (XXE) 💎 1039082 NEW Avoid using TransformerFactory without restriction of XML External Entity Reference (XXE) 💎 1039080 NEW Avoid using SchemaFactory without restriction of XML External Entity Reference (XXE) 💎 1039078 Rule nenamed “Avoid using XMLInputFactory without restriction of XML External Entity Reference (XXE)”. Raise violation when flag XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES is used alone and check for other flags. 💎 1039040 Raise violation when flag XMLConstants.FEATURE_SECURE_PROCESSING is used alone and check for other flags - for “Avoid using XMLReader without restriction of XML External Entity Reference (XXE)”. 💎 1039036 Check for flags other than XMLConstants.FEATURE_SECURE_PROCESSING for “Avoid using SAXParserFactory without restriction of XML External Entity Reference (XXE)”. 💎 1039034 Check for flags other than XMLConstants.FEATURE_SECURE_PROCESSING for “Avoid using DocumentBuilder without restriction of XML External Entity Reference (XXE)”. 💎 1039032 Update documentation for “Avoid creating cookie without setting httpOnly option (JEE)”. 💎 1039026 Update documentation for “Avoid using unsecured cookie (JEE)”. 💎 1039024 Fix false positive when seeding with SecureRandom.generateSeed() for “Avoid using predictable SecureRandom Seeds”. 💎 1039006 1.5.0-beta1
1.5.0-beta1
Change scope and improve coverage for the rule “Avoid using the Non-Serializable Object Stored in Session” 💎 1039068 Added support for the class" javax.crypto.spec.PBEKeySpec" for the rule “Avoid using Insecure PBE Iteration Count”. 💎 1039022 Improved the coverage of the rule: “Avoid using cryptography hash with hard-coded salt”. 💎 1039018 Improved the coverage of the rule: “Avoid using risky cryptographic hash (JEE)”. 💎 1039010 1.5.0-alpha1
1.5.0-alpha1
Improved the coverage of the rule: “Avoid Http Session without expiration”. 💎 1039052 Improved the coverage of the rule: “Avoid using Insecure PBE Iteration Count”. 💎 1039022 Improved the coverage of the rule: “Avoid using predictable SecureRandom Seeds”. 💎 1039006 Improved the coverage of the rule: “Avoid using HttpServletRequest.getRequestedSessionId()”. 💎 1039004 NEW Added the following new rule: “Avoid using HttpURLConnection with HTTP protocol”. 💎 1039076