20 Jun 2024
This update includes changes to the internal agents. The internal scan agent’s current version is 24.6.1. The internal authentication verifier agent’s current version is 24.6.1.
Fixes
- Fixed the screenshot error on Linux Agents.
13 Jun 2024
This update includes changes to the internal agents. The internal scan agent’s current version is 24.6.0. The internal authentication verifier agent’s current version is 24.6.0.
New Features
- Added functionality for scanning gRPC API Web Services → Learn more
New Security Checks
- Added a new attack pattern for missing Open Redirection
Improvements
- Updated to the latest Chromium version to improve security and performance → Learn more
- Added an option to trigger only specified lists of events
- Added a 100MB limit to the maximum total file size for imported link files
- Added an option to the GitHub Actions CI/CD integration to fail a build if a vulnerability with a specific severity is found during the scan
- Added a Y-axis to the Severity Trend graph in the dashboard
- Updated all the IAST Sensors:
- .NET Framework and .NET Core 6.2.0
- Java 16.0.0
- Node.js 2.1.3
- PHP 8.0.1
- Adjusted the behavior of the website matching option in the Discovery Settings to remove 2nd level domain matching in order to improve the relevance of discovery results
- Added a new option to the Discovery Match Settings (enabled by default) to only show discovery results that have an IP address. This change is intended to prevent the consumption of licenses on targets that cannot be scanned due to the lack of an actual IP address.
- Updated the summary information of the PCI compliance report
Fixes
- Fixed a bug in the Service Now Integration
- Fixed the issue that was causing activity logs to display incorrect owners of failed scans
- Fixed an issue with user-agent selection in scan policies that was causing disabled security check vulnerabilities to appear in the dashboards and scan reports
- Fixed an issue that was causing the agent to not send a heartbeat and become unavailable while archiving and uploading scan results
- Fixed the issue that was preventing updates made in Azure Boards from reflecting in Invicti Enterprise
- Fixed vulnerabilities with the Invicti Scan Agent Docker image
- Fixed the disk space utilization issue that was causing the InvictiCommon folder size to increase significantly during scans
- Resolved an issue with the Business Logic Recorder
- Improved the crawling capability to allow for automatic crawling of XHR requests
- Fixed the missing technology details on the scan summary and scan report pages
- Fixed an AWS4Signer authentication issue
11 Jun 2024
Fixes
- Updated the Auth Verifier Service database to resolve a problem with authentication verifier agents going offline
04 Jun 2024
This update includes changes to the internal agents. The internal scan agent’s current version is 24.5.2. The internal authentication verifier agent’s current version is 24.5.2.
Improvements
- Enhanced the engine’s ability to recognize API operations while scanning
28 May 2024
This update includes changes to the internal agents. The internal scan agent’s current version is 24.5.1. The internal authentication verifier agent’s current version is 24.5.1.
New Security Checks
- Added detection of Fortinet vulnerabilities (CVE-2020-12812, CVE-2019-5591, CVE-2018-13379)
Improvements
- Added a “Stop The Scan When Build is Aborted” option to the Jenkins integration
Fixes
- Fixed a bug in the user timeout session setting
- Resolved an issue with the frequency of out-of-date technology email notifications
- Removed email notifications for out-of-date technologies in failed scans
- Fixed an issue that was causing scans to be stuck in an async archiving state
- Fixed a bug in the automatic sign out functionality when the session timeout period has expired
- Fixed an issue in the detection of the ‘Improper XML parsing leads to Billion Laughs Attack’ vulnerability
07 May 2024
This update includes changes to the internal agents. The internal scan agent’s current version is 24.5.0. The internal authentication verifier agent’s current version is 24.5.0.
New Security Checks
- Added detection method for Angular
- Added a new security check for Oracle EBS RCE
Improvements
- Updated all IAST sensors to support Java 17 and 21
Fixes
- Fixed an issue with the detection method for wp-admin vulnerabilities
- Fixed the issue where scan profiles could not be created through automation tools, Postman, or through the Invicti API Documentation page
- Fixed the issue with scans that were stuck in ‘Delayed’ or ‘Archiving’ status
- Fixed an issue that was occurring with the Jira Integration when the Jira URL was set as Localhost
- Fixed a scan authentication issue and a crawling issue with Cloud Agents
- Fixed an issue that was occurring when websites were added with both http and https protocols
- The scan report pdf file name now includes the time and date when it is delivered via the scan completed notification
- Fixed the 504 error that was appearing when running the Scans_NewWithProfile endpoint
- Fixed a bug that was preventing retest scans from launching
- Fixed an issue with the scan data import from Invicti Enterprise to Invicti Standard
- Fixed the HTTP 401 forbidden response form authentication error
- Fixed a scan issue that was producing 413 error responses
17 Apr 2024
This update includes changes to the internal agents. The internal scan agent’s current version is 24.4.0. The internal authentication verifier agent’s current version is 24.4.0.
Improvements
- Improved AWS Secret Key ID detection security checks
- Improved Google Cloud API Key detection security checks
- Updated remediation information for Angular JS related vulnerabilities
- Improved Boolean-Based MongoDB Injection detection method
Fixes
- Fixed a validation error when validating Shark settings
- Fixed a bug in the API Access settings
- Resolved an issue with custom severity levels that were reverting to their previous level
- Fixed a bug in the API update command for scan profiles
- Removed limits on AWS Discovery port filters
- Technologies identified during failed scans are no longer displayed
- Fixed a bug in the scan retention period settings that was causing inaccurate information in the Recent Scans list
- The Last Login Date is now aligned between the UI and the API
- Fixed an issue that caused proxy usage for Chromium even when no proxy was selected from the scan policy settings
28 Mar 2024
This update includes changes to the internal agents. The internal scan agent’s current version is 24.3.1. The internal authentication verifier agent’s current version is 24.3.1.
New features
- Provided a new encryption method of API Token for Agent/Verifier Agent
- The CVSS 4.0 scores are now available via API
- A new feature to make the Discovery settings more precise – ability to include/exclude main level domains – reached Early Access for selected customers
- The pre-request script will now have the capability to generate AWS signature tokens to perform authentication
New security checks
- Added a new security check for TLS/SSL certificate key size too small issue
- Added a new security check for CVE-2023-46805 / CVE-2024-21887
- Added a new signature for Stack Trace Disclosures (ASP.Net)
- Added a new security checks for Client-Side Prototype Pollution
- Added a new Security Check that allows to report two vulnerabilities: TorchServe Management API Publicly Exposed and TorchServe Management API SSRF (CVE-2023-43654)
- Command Injection in VMware Aria Operations for Networks can now be detected
Improvements
- Improved WP Config detection over backup files
- Report template of Possible XSS is updated to cover mime sniffing
- The Agent type (Arm or Intel) information is displayed on the Scan Summary page
- The Permissions on the General Settings screen are now grouped by category rather than listed without being categorised
- A feature allowing the enabling or disabling of the JavaScript Parser has been added, facilitating JavaScript parameter discovery within the JavaScript code
- Fixed the issue where the Jenkins plug-in sent requests directly to the default gateway instead of routing them through the proxy
- The Team Administrator role checkbox is now in a separate ‘Limiting Permissions Role’ section
Fixes
- Disabled the BREACH Security Engine
- Increased the default Severity level of Version Disclosure (Varnish) from ‘Information’ to ‘Low’
- Fixed the issue where users were unable to load the Scan Report
- Fixed the issue where Internal Scans were not failing if their Agents were terminated
- Fixed the Azure Boards integration, which was reported to have been suspended by itself
- Fixed the issue where the customer couldn’t scan their target with the additional website properly
- Fixed query optimization on the main Scans page, resulting in improved response time and query quality
- The page number in the Custom Script Editor is now correctly displayed
- When the Token is expired, the Azure Boards Integration is disabled
- Fixed concurrency exceptions occurring for the scan and website tables due to excessive update requests sent within a short timeframe
- Fixed the inability to export a scan from Invicti Standard to Invicti Enterprise
- The Issues counter on the Dashboard now displays the correct number of issues
- Fixed the inability of the custom script editor to load the form authentication fields
- Fixed an issue when Team Administrator and Account Owner role are assigned to the same user
13 Mar 2024
This update includes changes to the internal agents. The internal scan agent’s current version is 24.3.0. The internal authentication verifier agent’s current version is 24.3.0.
New features
- ServiceNow Application Vulnerability Response integration is now available in the ServiceNow store
- Added the ability to force authentication verifier agent to use incognito by default on Chromium browser
New security checks
- Added detection for ActiveMQ RCE to the OOB RCE Attack Pattern (CVE-2023-46604)
Improvements
- Improved ServiceNow Vulnerability Response integration
Fixes
- Fixed the error in the API’s websites/update function
- Removed logos and brand names from the Detailed Scan Report display
- The API now correctly assigns the appropriate scan profile when updating the periods of scheduled scans
- Fixed the hyperlink to the Release Notes within the application
- Upgraded Microsoft.Owin package to version number 4.2.2
- Fixed null character error in JIRA integration when sending issues
- Fixed the system to halt subsequent tests if a scan is aborted from Jenkins
- Scan policies can now be updated with proxy passwords directly through the API
- Fixed GUI and API login dates to synchronize seamlessly
- Added Cookie Source field to the Knowledge Base Cookies screen
- The CSV export for user lists now includes all attributes that have been selected
20 Feb 2024
This update includes changes to the internal agents. The internal scan agent’s current version is 24.2.0. The internal authentication verifier agent’s current version is 24.2.0.
New security checks
- Implemented a detection and reporting mechanism for the Backup Migration WordPress plugin (CVE-2023-6553)
- Added detection for TinyMCE
Improvements
- Updated the “Insecure Transportation Security Protocol Supported (TLS 1.0)” vulnerability to High Severity
- Implemented support for scanning sites with location permission pop-ups
- Implemented support for FreshService API V2
- Revised the labeling of the active vulnerabilities information on the Scan Summary page to provide greater clarity
- Removed obsolete X-Frame-Options Header security checks
Fixes
- Fixed a bug in the Request/Response tab of Version Disclosure vulnerabilities
- Corrected an issue in the technical reports where vulnerabilities identified in Korean are now reported in English
- Changed the ID parameter from ‘optional’ to ‘required’ within the Scan Policy Update API
- Removed the target URL from the scope control list
- Resolved a bug in the filtering of vulnerabilities on the Issues page
- Fixed a bug in the marking of issues as a false positive
- Resolved an issue where the agent would become unavailable after receiving a 401 error
- Fixed the issue with uploading a Swagger file into a scan profile
30 Jan 2024
This update includes changes to the internal agents. The internal scan agent’s current version is 24.1.1. The internal authentication verifier agent’s current version is 24.1.1.
New features
- Added the option to remove Request/Response details from the detailed template to avoid the character limit error when sending vulnerabilities
- Added the option for customers to display their company name on the PCI report (new scan settings field under General settings)
- Enabled the ability to re-scan a previously scanned target which allows the application of previous exclusions on the scan and helps avoid false positives on the PCI ASV scan
- Added the option to enable enhanced logging of failed logins
- Added functionality to the UI for users to obtain logs from failed scans (previously only system administrators were able to do that)
New security checks
- Added a check for dotCMS
- Added a check for the Ultimate Member WordPress plugin
- Added a new mXSS pattern
- Added new signatures to detect JWKs
Improvements
- Improved the recommendations for the Weak Ciphers Enabled vulnerability
- Improved detection of swagger.json vulnerabilities
Fixes
- Fixed a bug in the cloning report policies functionality
- Fixed an error that was occurring with the API endpoint: list-scheduled
- Fixed a bug with the Jira integration
- Fixed a bug with custom scheduled scans that were not updating the Next Execution Time field correctly
- Fixed an issue with the HashiCorp Vault integration token validation path
- Fixed the missing ‘Known Issues’ tab from scan summary issue details
- Fixed an issue with the severity trend chart on the Dashboard
- Fixed a problem with importing WDSL files
09 Jan 2024
This update includes changes to the internal agents. The internal scan agent’s current version is 24.1.0. The internal authentication verifier agent’s current version is 24.1.0.
New features
- Added notifications about agent disk full issues for easier navigation and to prevent scan errors
- Added an option to the Jenkins plugin to cancel the scan started by the plugin if the Jenkins build is aborted
Improvements
- Improved reporting of DOM XSS vulnerabilities
Fixes
- Fixed an issue with removing the client certificate via API
- Fixed an inconsistency for PCI results between the Invicti UI and the PCI DSS detailed report
- Fixed a bug that was causing scan session files to fail when loading
- Fixed inconsistencies with the ‘average time to fix’ table on the dashboard
- Fixed an issue with the import of scan data from Invicti Enterprise to Invicti Standard
- Fixed an issue with the form verifier not using the new scan policy until the scan profile is saved
- Added a custom detailed scan report
- Fixed a bug in the importing of links
- Fixed an error that was occurring when setting an issue as Accepted Risk
- Resolved issues with importing API documentation from a link
- Resolved issues with the Authentication Verifier and Agent.db file corrupting after update
- Fixed a bug in the Jenkins plugin that was causing the ‘Stop The Scan When Build Fails’ option to not work correctly