Help Needed! Configuring Risk Levels in ZAP CLI

282 views
Skip to first unread message

Zap BotStan

unread,
Jul 29, 2021, 6:00:31 PM7/29/21
to OWASP ZAP User Group

A question on Risk Levels, is there any way one can change the default risk levels of a vulnerability?
For example,

Name                                                                             Risk Level         New level
Content Security Policy (CSP) Header Not Set
      Medium              High
Multiple X-Frame-Options Header Entries              Medium               Low
Application Error Disclosure
                                     Low
                      Medium
Cookie Without SameSite Attribute
                         Low                      Medium

currently the zap cli can change a threshold, but can this be done for a Risk Level? Any assistance would be great!

kingthorin+owaspzap

unread,
Jul 29, 2021, 8:02:53 PM7/29/21
to OWASP ZAP User Group

Raj Dev

unread,
Jul 29, 2021, 8:40:19 PM7/29/21
to OWASP ZAP User Group
Hi owuor,

The Alert Filters add-on will work with only the older Jenkins plugin and ZAP UI. But it will not work in the Docker, Zap-Cli and openshift solution. Hopefully, a new feature comes in the new ZAP framework:

Also,  on August 4th, the ZAP team has a webinar regarding the Automation Framework. I wish you to don't miss it.
August 4

Thanks,
Raj Dev

kingthorin+owaspzap

unread,
Jul 29, 2021, 9:01:45 PM7/29/21
to OWASP ZAP User Group
It will work with docker, if you're driving via the API. Or using custom hooks with the packaged scans.

Zap BotStan

unread,
Jul 30, 2021, 2:04:38 PM7/30/21
to OWASP ZAP User Group
Hi team, @kingthorin+owaspzap it works!!!! we were able to use curl to re-label the rule ID and change the value. Thank you!

kingthorin+owaspzap

unread,
Jul 30, 2021, 3:14:00 PM7/30/21
to OWASP ZAP User Group
No problem. Thanks for letting us know.

Zap BotStan

unread,
Aug 2, 2021, 12:00:44 PM8/2/21
to OWASP ZAP User Group


Hahaha i would not miss it for the world!!!!
On Thursday, July 29, 2021 at 8:40:19 PM UTC-4 dev4...@gmail.com wrote:
Reply all
Reply to author
Forward
0 new messages