Release Date:
New Detections
-
Added detection of certificates whose private key is publicly known, such as keys affected by the Debian OpenSSL vulnerability or ROCA.
-
Added detection of RSA certificate keys that can easily be factored.
-
Added detection of certificates that share a public key or an RSA prime factor with another certificate in the same scan.
-
Added detection of certificates with invalid serial numbers.
-
Added detection of NLnet Labs Unbound DNS servers.
-
Added detection of catch-all web virtual hosts that serve content not reachable through any declared virtual host.
-
Added technology fingerprints for the following:
-
18 WordPress plugins, including Elementor, Jetpack, Smart Slider 3 and GTranslate
-
DOMPurify
-
Hugo
-
CKAN
-
Bug Fixes and Minor Improvements
-
Certificate issues on services scanned without virtual hosts are now reported regardless of the IP virtual host setting.
-
Certificate issues affecting every configured virtual host of a service are now reported once for the service instead of once per virtual host.
-
TLS protocol and cipher results are no longer reported twice for the same service.
-
Weak certificate keys are now detected on every certificate in the chain.
-
Improved detection of Drupal, Plone, TYPO3, nginx and JFrog Artifactory.
-
The CrushFTP authentication bypass check no longer interprets timeouts as an indication of vulnerability.
-
Improved the reliability of checks against slow or unresponsive targets.
-
Malformed TLS responses no longer interrupt the TLS scan.