Your app suffers from Session ID in URL Rewrite which can facilitate session fixation attacks. (https://www.google.com/search?q=session+id+in+url+rewrite+owasp)
My guess is that since almost every home requests generates a new re-written URL with unique session ID then ZAP treats that as a separate URL.
--
You received this message because you are subscribed to a topic in the Google Groups "OWASP ZAP User Group" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/zaproxy-users/FmODmgOXUeA/unsubscribe.
To unsubscribe from this group and all its topics, send an email to zaproxy-user...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.