Alertfilter New risk is not showing up in ExportReport

18 views
Skip to first unread message

Thoni A

unread,
Nov 17, 2020, 2:59:47 PM11/17/20
to ZAP Jenkins Plugin
Hi ALL,
we are testing a sample application using Jenkins ZAP plugin with the following  alertfilter definition below. The reports that are generated with ExportReport plugin do not show the new risk levels as per the definition below, except marking one of the URL 's confidence as false positive. However when we open the ZAP session from Jenkins  in ZAP UI we see all the URL'S  have new risk assigned correctly.
Is there bug in the plugin that generates ExportReport ??
Is there any resolution so that reports are genetated with correct risk levels per URL'S ??.

<?xml version="1.0"?>
<alertfilters>
<alertfilter>
<ruleId>10021</ruleId>
        <newLevel>2</newLevel>
        <urlIsRegex>false</urlIsRegex>
        <parameter>X-Content-Type-Options</parameter>
        <paramregex>false</paramregex>
        <attack/>
                <attackregex>false</attackregex>
                <evidence/>
                <evidenceregex>false</evidenceregex>
<enabled>true</enabled>
</alertfilter>
<alertfilter>
<ruleId>10021</ruleId>
        <newLevel>-1</newLevel>
        <urlIsRegex>false</urlIsRegex>
        <parameter>X-Content-Type-Options</parameter>
        <paramregex>false</paramregex>
        <attack/>
                <attackregex>false</attackregex>
                <evidence/>
                <evidenceregex>false</evidenceregex>
<enabled>true</enabled>
</alertfilter>
<alertfilter>
<ruleId>10021</ruleId>
        <newLevel>0</newLevel>
        <urlIsRegex>false</urlIsRegex>
        <parameter>X-Content-Type-Options</parameter>
        <paramregex>false</paramregex>
        <attack/>
                <attackregex>false</attackregex>
                <evidence/>
                <evidenceregex>false</evidenceregex>
<enabled>true</enabled>
</alertfilter>
<alertfilter>
<ruleId>10021</ruleId>
        <newLevel>3</newLevel>
        <urlIsRegex>false</urlIsRegex>
        <parameter>X-Content-Type-Options</parameter>
        <paramregex>false</paramregex>
        <attack/>
                <attackregex>false</attackregex>
                <evidence/>
                <evidenceregex>false</evidenceregex>
<enabled>true</enabled>
</alertfilter>
</alertfilters>

thanks 
Thoni

Reply all
Reply to author
Forward
0 new messages