Bug Triage and Reporting
Introducing GitLab browser-based active checks in DAST

Introducing GitLab browser-based active checks in DAST

10/10/2023 · Cameron Swords

What this post added

Introduced browser-based active checks for DAST, starting with path traversal vulnerability detection (GitLab check 22.1) to replace ZAP alert 6. This enables more effective detection of vulnerabilities in modern web applications. Active checks are defined in YAML and can include match response, timing, and callback attack types. A worked example demonstrates how path traversal attacks are constructed and detected.

Read the original post ↗