Invicti Enterprise On-Demand 14 Jan 2025 v25.1.0
This update includes changes to the internal agents. The internal scan agent’s current version is 25.1.0. The internal authentication verifier agent’s current version is 25.1.0.
New features
- Clicking on the scheduled scan icon in the scan summary screen now redirects you to the Recent Scans page with a filtered view, improving navigation and access to relevant scan details
- Implemented an integration that automatically retrieves the latest Container security results from Mend when a DAST scan is initiated
Improvements
- Fixed an issue on the 2FA page where the code text field was not automatically focused upon page load
- Introduces a configurable retention period for HTTP log files, allowing Root users to specify the number of days before log
- Implemented a restriction to prevent the modification of the Vulnerability Signature Type
- Enhanced the UI to highlight the menu when API Hub specifications are linked to a scan profile, making it easier for users to identify associated profiles
- Updated Chromium from version 121 to version 131 for enhanced performance and compatibility
- Enhanced detection accuracy for Weak Ciphers Enabled by analyzing false positives
- Administrators can now assign Agent Groups to Teams for greater control over agents and the teams that can use them. Learn more.
Resolved issues
- Corrected OTP configuration attachment to personas, ensuring separate secrets and preventing shared changes
- Resolved issue where the internal agent service stopped after being disabled in the UI. The service now remains active even when the agent is disabled from the web application.
- Updated the SharedAssemblyInfo file to reflect the correct copyright details
- Fixed an issue where a disabled scan was inadvertently running, leading to an outage
- Fixed a bug where users were unable to update the website name longer than 40 characters
- Fixed an issue where the Invicti REST API did not return errors when importing an invalid definition file
- Resolved the “Internal Server Error” encountered on the Invicti scans/report API endpoint after enabling the “Prevent any sensitive information showing within the product” setting
- Fixed an issue where the Issue state was inadvertently removed when a user, without permission to update the state, added a note to the issue
- Fixed an issue where the “Notification Settings” hyperlink in notification emails was redirecting incorrectly
- Resolved the issue where the Agent Verifier was encountering errors when using certificates in a Linux environment
- Fixed an issue where duplicate tickets were being created in ServiceNow due to integration error
- Fixed an issue where the severity trend chart was not rendering correctly on the individual website dashboard
- Node.js v6 has reached its End of Life (EOL), and support for this version has been removed from Azure Pipelines
- Resolved a coverage issue where the login page reappeared during scans