Release Notes - 1.5


  • 1.5.5-funcrel

    1.5.5-funcrel
    Updates embedded libraries.
    Updates internal evaluation engine leading to an overall enhancement of the accuracy of several security rules. 📝 44211
  • 1.5.4-funcrel

    1.5.4-funcrel
    Updated embedded libraries.
  • 1.5.3-funcrel

    1.5.3-funcrel
    THIS VERSION WAS RELEASED BY ACCIDENT AND HAS BEEN DELETED FROM EXTEND.
  • 1.5.2-funcrel

    1.5.2-funcrel
    Fixes an error generating the message in the analysis log: “AttributeError: ‘MemberAccess’ object has no attribute ‘get_name’”.
    Fix missing violation for rule “Avoid using XPathFactory without restriction of XML External Entity Reference (XXE)” when setting the initial value of an Xpath field. 💎 1039038
    Fix false positive for rule “Avoid using the Non-Serializable Object Stored in Session” when Object has an inner class. 💎 1039068
    Fix missing violation for rule “Avoid creating cookie without setting httpOnly option (JEE)” when calling HttpServletResponse.addHeader(). 💎 1039026
    Fix missing violation for rule “Avoid using unsecured cookie (JEE)” when calling HttpServletResponse.addHeader(). 💎 1039024
  • 1.5.1-funcrel

    1.5.1-funcrel
    Fix false positive for rule “Avoid using TransformerFactory without restriction of XML External Entity Reference (XXE)”. 📝 48146
    Fixed the “RuntimeError: property is not registered for given object type” when analyzing java classes that have initialization blocks.
    Fix error “AttributeError: ‘Object’ object has no attribute ‘get_inherited_types’” when analyzing a java.util.Map for rule “Avoid using the Non-Serializable Object Stored in Session”. 💎 1039068
    Fix mixing violation of rule “Avoid using XPathExpression without a configurable secure parser (XXE)” for instances created with a call to XPathFactory.newDefaultInstance(). 💎 1039094
    Fix mixing violation of rule “Avoid using XMLInputFactory without restriction of XML External Entity Reference (XXE)” for instances created with a call to XMLInputFactory.newFactory(). 💎 1039040
  • 1.5.0-funcrel

    1.5.0-funcrel
    Fixed missing violations for the rule “Avoid using the Non-Serializable Object Stored in Session”. 💎 1039068
    NEW Ensure secure option is enabled when creating session (JEE) 💎 1039098
    NEW Ensure httpOnly option is enabled when creating session (JEE) 💎 1039096
    Changed the specifications of rule “Avoid creating cookie without setting httpOnly option (JEE)”. The “web.xml” configuration file is no longer a remediation for this rule. 💎 1039026
    Changed the specifications of rule “Avoid using unsecured cookie (JEE)”. The “web.xml” configuration file is no longer a remediation for this rule. 💎 1039024
  • 1.5.0-beta3

    1.5.0-beta3
    Fixes false negative for the rule 1039062: “Always implement readObject() to prevent untrusted deserialization when loading from ObjectInputStream”. 📝 44850
    Fixes false negative for the rule “Avoid using DocumentBuilder without restriction of XML External Entity Reference (XXE)” when calling method createXMLEventReader(). 💎 1039040
    Fixes false positive for the rule: “Avoid using DocumentBuilder without restriction of XML External Entity Reference (XXE)” when using setEntityResolver(). 💎 1039034
    Fixes false positive for the rule: “Avoid using DocumentBuilder without restriction of XML External Entity Reference (XXE)” when using setEntityResolver(). Bookmark was moved to the call to parse() method. 💎 1039032
    NEW Avoid using XPathExpression without a configurable secure parser (XXE) 💎 1039094
    NEW Avoid using JAXB Unmarshaller without a configurable secure parser (XXE) 💎 1039092
    NEW Avoid using java.beans.XMLDecoder (XXE) 💎 1039090
    NEW Avoid using Validator without restriction of XML External Entity Reference (XXE) 💎 1039088
    NEW Avoid using DOMParser without restriction of XML External Entity Reference (XXE). 💎 1039086
  • 1.5.0-beta2

    1.5.0-beta2
    NEW Avoid using SAXBuilder without restriction of XML External Entity Reference (XXE) 💎 1039084
    NEW Avoid using SAXTransformerFactory without restriction of XML External Entity Reference (XXE) 💎 1039082
    NEW Avoid using TransformerFactory without restriction of XML External Entity Reference (XXE) 💎 1039080
    NEW Avoid using SchemaFactory without restriction of XML External Entity Reference (XXE) 💎 1039078
    Rule nenamed “Avoid using XMLInputFactory without restriction of XML External Entity Reference (XXE)”. Raise violation when flag XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES is used alone and check for other flags. 💎 1039040
    Raise violation when flag XMLConstants.FEATURE_SECURE_PROCESSING is used alone and check for other flags - for “Avoid using XMLReader without restriction of XML External Entity Reference (XXE)”. 💎 1039036
    Check for flags other than XMLConstants.FEATURE_SECURE_PROCESSING for “Avoid using SAXParserFactory without restriction of XML External Entity Reference (XXE)”. 💎 1039034
    Check for flags other than XMLConstants.FEATURE_SECURE_PROCESSING for “Avoid using DocumentBuilder without restriction of XML External Entity Reference (XXE)”. 💎 1039032
    Update documentation for “Avoid creating cookie without setting httpOnly option (JEE)”. 💎 1039026
    Update documentation for “Avoid using unsecured cookie (JEE)”. 💎 1039024
    Fix false positive when seeding with SecureRandom.generateSeed() for “Avoid using predictable SecureRandom Seeds”. 💎 1039006
  • 1.5.0-beta1

    1.5.0-beta1
    Change scope and improve coverage for the rule “Avoid using the Non-Serializable Object Stored in Session” 💎 1039068
    Added support for the class" javax.crypto.spec.PBEKeySpec" for the rule “Avoid using Insecure PBE Iteration Count”. 💎 1039022
    Improved the coverage of the rule: “Avoid using cryptography hash with hard-coded salt”. 💎 1039018
    Improved the coverage of the rule: “Avoid using risky cryptographic hash (JEE)”. 💎 1039010
  • 1.5.0-alpha1

    1.5.0-alpha1
    Improved the coverage of the rule: “Avoid Http Session without expiration”. 💎 1039052
    Improved the coverage of the rule: “Avoid using Insecure PBE Iteration Count”. 💎 1039022
    Improved the coverage of the rule: “Avoid using predictable SecureRandom Seeds”. 💎 1039006
    Improved the coverage of the rule: “Avoid using HttpServletRequest.getRequestedSessionId()”. 💎 1039004
    NEW Added the following new rule: “Avoid using HttpURLConnection with HTTP protocol”. 💎 1039076