RedHatProductSecurity / rapidast

RapiDAST enables simple, continuous and fully automated application security testing
Apache License 2.0
59 stars 39 forks source link

[ZAP] start by configuring passive scanner #137

Closed cedricbu closed 1 year ago

cedricbu commented 1 year ago

All request pass through the passive scan. So the passive scan needs to take place before we load any API (such as openAPI loading), otherwise those will be treated with a default passive scan.

jeremychoi commented 1 year ago

nice finding and fix. LGTM.