Skip to content

Commit caf57d8

Browse files
authored
Merge pull request #6758 from zapbot/scan-policies-updt
Update scan policies based on Tags
2 parents 610675c + 286c30d commit caf57d8

File tree

2 files changed

+108
-0
lines changed

2 files changed

+108
-0
lines changed

addOns/scanpolicies/CHANGELOG.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,9 @@ All notable changes to this add-on will be documented in this file.
44
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/).
55

66
## Unreleased
7+
### Changed
8+
- Updated based on Rules' Policy Tag assignments.
9+
710
### Added
811
- QA CI/CD scan policy help.
912

Lines changed: 105 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,105 @@
1+
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
2+
<configuration>
3+
<policy>QA CI/CD</policy>
4+
<scanner>
5+
<level>OFF</level>
6+
<strength>MEDIUM</strength>
7+
</scanner>
8+
<plugins>
9+
<p0>
10+
<name>Directory Browsing</name>
11+
<enabled>true</enabled>
12+
<level>MEDIUM</level>
13+
</p0>
14+
<p10058>
15+
<name>GET for POST</name>
16+
<enabled>true</enabled>
17+
<level>MEDIUM</level>
18+
</p10058>
19+
<p20012>
20+
<name>Anti-CSRF Tokens Check</name>
21+
<enabled>true</enabled>
22+
<level>MEDIUM</level>
23+
</p20012>
24+
<p20019>
25+
<name>External Redirect</name>
26+
<enabled>true</enabled>
27+
<level>MEDIUM</level>
28+
</p20019>
29+
<p40009>
30+
<name>Server Side Include</name>
31+
<enabled>true</enabled>
32+
<level>MEDIUM</level>
33+
</p40009>
34+
<p40012>
35+
<name>Cross Site Scripting (Reflected)</name>
36+
<enabled>true</enabled>
37+
<level>MEDIUM</level>
38+
</p40012>
39+
<p40018>
40+
<name>SQL Injection</name>
41+
<enabled>true</enabled>
42+
<level>MEDIUM</level>
43+
</p40018>
44+
<p40040>
45+
<name>CORS Header</name>
46+
<enabled>true</enabled>
47+
<level>MEDIUM</level>
48+
</p40040>
49+
<p40044>
50+
<name>Exponential Entity Expansion (Billion Laughs Attack)</name>
51+
<enabled>true</enabled>
52+
<level>MEDIUM</level>
53+
</p40044>
54+
<p50000>
55+
<name>Script Active Scan Rules</name>
56+
<enabled>true</enabled>
57+
<level>MEDIUM</level>
58+
</p50000>
59+
<p90017>
60+
<name>XSLT Injection</name>
61+
<enabled>true</enabled>
62+
<level>MEDIUM</level>
63+
</p90017>
64+
<p90020>
65+
<name>Remote OS Command Injection</name>
66+
<enabled>true</enabled>
67+
<level>MEDIUM</level>
68+
</p90020>
69+
<p90021>
70+
<name>XPath Injection</name>
71+
<enabled>true</enabled>
72+
<level>MEDIUM</level>
73+
</p90021>
74+
<p90023>
75+
<name>XML External Entity Attack</name>
76+
<enabled>true</enabled>
77+
<level>MEDIUM</level>
78+
</p90023>
79+
<p90025>
80+
<name>Expression Language Injection</name>
81+
<enabled>true</enabled>
82+
<level>MEDIUM</level>
83+
</p90025>
84+
<p90026>
85+
<name>SOAP Action Spoofing</name>
86+
<enabled>true</enabled>
87+
<level>MEDIUM</level>
88+
</p90026>
89+
<p90029>
90+
<name>SOAP XML Injection</name>
91+
<enabled>true</enabled>
92+
<level>MEDIUM</level>
93+
</p90029>
94+
<p90035>
95+
<name>Server Side Template Injection</name>
96+
<enabled>true</enabled>
97+
<level>MEDIUM</level>
98+
</p90035>
99+
<p90037>
100+
<name>Remote OS Command Injection (Time Based)</name>
101+
<enabled>true</enabled>
102+
<level>MEDIUM</level>
103+
</p90037>
104+
</plugins>
105+
</configuration>

0 commit comments

Comments
 (0)