OpenRASP v1.1 released

43 views
Skip to first unread message

OpenRASP

unread,
Jun 5, 2019, 11:22:41 PM6/5/19
to OpenRASP

https://github.com/baidu/openrasp/releases/tag/v1.1


Breaking changes

General changes

  • Upgrade Google V8 to v7.2
  • Reduced memory usage by replacing ANTLR4 with Flex

PHP agent

  • Removed pcre dependency
  • Replaced libstdc++ with libc++
  • Add Thread-Safety edition in binary releases

Java agent

  • Replace Mozilla Rhino with OpenRASP-v8 component
  • Removed native implementation of SQLi/SSRF detection algorithm
  • Temporarily disabled support of JRockit JDK.
    • WebLogic 10.3.6 still works with Oracle JDK, aka export JAVA_VENDOR=Sun

JavaScript plugin system

  • Removed console coloring support

New features

General changes

  • Add monitoring of MySQL authentication failure
  • Add detection of weak password for database connections

Java agent

  • Add a new algorithm xxe_disable_entity
Reply all
Reply to author
Forward
0 new messages