Problem:
When calling ZAP 2.15 via the zap-maven-plugin, as soon as a new commonlib (> commonlib-release-1.25.0.zap which is contained in the download bundle) is available and installed, for each of the 49 passive rules the following warning & error appears in zap.log (full log below):
50419 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Installing new addon commonlib v1.28.0
50771 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule withthe name "Anti-clickjacking Header" already exists. The rule "org.zaproxy.zap.extension.pscanrules.AntiClickjackingScanRule" will not be loaded.
50771 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.AntiClickjackingScanRule
[..similar error for 48 other passive rules...]
50850 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Finished installing new addon commonlib v1.28.0
Notes:
If I directly place the most up-to-date version of commonlib in the ZAP installations plugin directory (as of now this is commonlib-release-1.28.0.zap), commonlib is not updated and the problem does not appear.
This Error is not fatal, ZAP continues with the analysis but this problem seems to have an impact on the analysis results, as I get slightly different results when I run ZAP with this error compared to when I apply the below mentioned "Workaround"
Workaround:
After looking at the log I saw that the exact same scanrules are already loaded in zap.log a few seconds before, e.g.
[ZAP-daemon] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Anti-clickjacking Header
When I removed the "pscanrules-release-58.zap" from the ZAP Installation directory, this earlier loading does not happen and according to zap.log, ZAP successfully downloads and installs all latest extensions, in particular
commonlib v1.28.0
pscanrules v61.0.0
Steps to reproduce the behavior:
the zapOptions in the configuration of the zap-maven-plugin is this (simplified)
<zapOptions>-daemon -silent -config start.checkForUpdates=false -config api.disablekey=true -config network.connection.httpProxy.enabled=true -config network.connection.httpProxy.host=${owasp.maven.proxy.host} -config network.connection.httpProxy.port=${owasp.maven.proxy.port} -config network.connection.httpProxy.exclusions.exclusion.host=${owaspZapTargetHost} -config network.connection.defaultUserAgent="${owaspZapDefaultUserAgent}" -dir ${owaspZapWork} -addoninstall pscanrulesAlpha -addoninstall pscanrulesBeta -addoninstall pscanrules -addoninstall ascanrulesAlpha -addoninstall ascanrulesBeta -addoninstall ascanrules -addoninstall spider -addoninstall spiderAjax -addoninstall reports -addoninstall webdriverwindows<zapOptions>
run mvn clean verify
Expected behavior:
ZAP should download and install all used extensions/plugins in their most up-to-date version without throwing any errors.
In this case it seems that the passive scanrules are initialized twice.
Software versions:
ZAP 2.15 (Core Cross Platform Package)
Screenshots:
No response
Errors from the zap.log file:
Basically as described, this time with more details:
590 [main] INFO org.zaproxy.zap.DaemonBootstrap - ZAP 2.15.0 started 30/09/2024, 11:29:22 with home: C:\path\to\project\target\owasp-zap-work\ cores: 20 maxMemory: 512 MB
615 [main] INFO org.parosproxy.paros.common.AbstractParam - Setting config start.checkForUpdates = false was null
615 [main] INFO org.parosproxy.paros.common.AbstractParam - Setting config api.disablekey = true was null
616 [main] INFO org.parosproxy.paros.common.AbstractParam - Setting config network.connection.httpProxy.enabled = true was null
616 [main] INFO org.parosproxy.paros.common.AbstractParam - Setting config network.connection.httpProxy.host = <httpproxy> was null
616 [main] INFO org.parosproxy.paros.common.AbstractParam - Setting config network.connection.httpProxy.port = 80 was null
617 [main] INFO org.parosproxy.paros.common.AbstractParam - Setting config network.connection.httpProxy.exclusions.exclusion.host = <zap-target-host> was null
617 [main] INFO org.parosproxy.paros.common.AbstractParam - Setting config network.connection.defaultUserAgent = Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko was null
1216 [ZAP-daemon] INFO org.zaproxy.zap.control.ExtensionFactory - Installed add-ons: [[id=ascanrules, version=66.0.0], [id=callhome, version=0.12.0], [id=commonlib, version=1.26.0], [id=database, version=0.4.0], [id=diff, version=15.0.0], [id=gettingStarted, version=17.0.0], [id=help, version=18.0.0], [id=invoke, version=15.0.0], [id=network, version=0.16.0], [id=oast, version=0.18.0], [id=onlineMenu, version=13.0.0], [id=pscanrules, version=58.0.0], [id=quickstart, version=47.0.0], [id=reports, version=0.32.0], [id=reveal, version=8.0.0], [id=spider, version=0.11.0], [id=tips, version=13.0.0]]
1217 [ZAP-daemon] INFO org.zaproxy.zap.control.ExtensionFactory - Loading extensions
1278 [ZAP-daemon] WARN org.zaproxy.zap.extension.script.ExtensionScript - No default JavaScript/ECMAScript engine found, some scripts might no longer work.
1428 [ZAP-daemon] INFO org.zaproxy.addon.network.internal.TlsUtils - Using supported SSL/TLS protocols: [TLSv1.2, TLSv1.3]
1584 [ZAP-daemon] INFO org.zaproxy.zap.control.ExtensionFactory - Extensions loaded
1678 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Auto-update Extension - Allows ZAP to check for updates
1684 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Options Extension - Options Extension
1684 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Edit Menu Extension - Edit Menu Extension
1684 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing API Extension - Provides a rest based API for controlling and accessing ZAP
1690 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing History Extension - History Extension
1690 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing ExtensionReveal - Show hidden fields and enable disabled fields
1691 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Search Extension - Search messages for strings and regular expressions
1692 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Breakpoint Extension - Allows you to intercept and modify requests and responses
1693 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Passive Scan Extension - Passive scanner
1699 [ZAP-daemon] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Stats Passive Scan Rule
1704 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Alerts Extension - Allows you to view and manage alerts
1705 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Active Scan Extension - Active scanner, heavily based on the original Paros active scanner, but with additional tests added
1710 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Standard Menus Extension - A set of common popup menus for miscellaneous tasks
1710 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Compare Extension - Compares 2 sessions and generates an HTML file showing the differences
1710 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing ExtensionInvoke - Invoke external applications passing context related information such as URLs and parameters
1710 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Anti-CSRF Extension - Handles anti cross site request forgery (CSRF) tokens
1712 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Authentication Extension - Authentication Extension
1720 [ZAP-daemon] INFO org.zaproxy.zap.extension.authentication.ExtensionAuthentication - Loaded authentication method types: [Form-based Authentication, HTTP/NTLM Authentication, Manual Authentication, Script-based Authentication, JSON-based Authentication]
1722 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Log4j Extension - Logs errors to the Output tab in development mode only
1722 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Users Extension - Users Extension
1723 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Parameters Extension - Summarise and analyse FORM and URL parameters as well as cookies
1723 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Script Extension - Script integration
1726 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Forced User Extension - Forced User Extension
1726 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing HTTP Sessions Extension - Extension handling HTTP sessions
1727 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing ExtensionDiff - ExtensionDiff
1727 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing HTTP Panel Post Table View Extension - HTTP Panel Post Table View Extension
1727 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Session Management Extension - Session Management Extension
1730 [ZAP-daemon] INFO org.zaproxy.zap.extension.sessions.ExtensionSessionManagement - Loaded session management method types: [Cookie-based Session Management, HTTP Authentication Session Management, Script-based Session Management]
1730 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing HTTP Panel Form Table View Extension - HTTP Panel Form Table View Extension
1730 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Core UI Extension - Core UI related functionality.
1730 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Authorization Extension - Authorization Extension
1730 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Refresh Sites Tree Extension - Adds menu item to refresh the Sites tree
1730 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Help Extension - ZAP User Guide
1731 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Call Home - Handles all of the calls to ZAP services
1740 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Network Extension - Provides core networking capabilities.
1758 [ZAP-daemon] INFO org.zaproxy.addon.network.ConnectionOptions - Unsafe SSL/TLS renegotiation disabled.
1759 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Extension Configuration Extension - Allows you to configure which extensions are loaded when ZAP starts
1759 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Combined HTTP Panels Extension - Combined HTTP Panels Extension
1759 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing HTTP Panel Hex View Extension - HTTP Panel Hex View Extension
1760 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing HTTP Panel Image View Extension - HTTP Panel Image View Extension
1760 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing HTTP Panel Query Table View Extension - HTTP Panel Query Table View Extension
1760 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing HTTP Panel Syntax Highlighter View Extension - HTTP Panel Syntax Highlighter View Extension
1760 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Keyboard Configuration Extension - Adds support for configurable keyboard shortcuts for all of the ZAP menus.
1760 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Scanner Rule Configuration Extension - Active and passive rule configuration
1761 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Statistics Extension - Statistics
1762 [ZAP-daemon] INFO org.zaproxy.zap.extension.stats.ExtensionStats - Start recording in memory stats
1762 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Custom Pages Extension - Custom Pages Definition
1763 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Active Scan Rules - Release status active scan rules
1763 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Common Library - A library of shared functionality
1763 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing ExtensionGettingStarted - The ZAP Getting Started Guide
1763 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Out-of-band Application Security Testing - Adds Out-of-band Application Security Testing functionality.
2010 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing ExtensionOnlineMenu - The Online menu links
2010 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Passive Scan Rules - Release status passive scan rules
2010 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Quick Start panel - Adds the Quick Start panel for scanning and exploring applications
2011 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Quick Start Spider Integration - Adds the option to use the traditional Spider in the Quick Start scan.
2012 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Report Generator - Templated and themed report generation functionality
2012 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing Spider Extension - Spider used for automatically finding URIs on a site.
2020 [ZAP-daemon] INFO org.parosproxy.paros.extension.ExtensionLoader - Initializing ExtensionTipsAndTricks - Tips and Tricks
2175 [ZAP-daemon] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Anti-clickjacking Header
2175 [ZAP-daemon] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Application Error Disclosure
[more rules]
2178 [ZAP-daemon] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: X-Debug-Token Information Leak
2178 [ZAP-daemon] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Server Leaks Information via "X-Powered-By" HTTP Response Header Field(s)
2471 [ZAP-daemon] INFO org.flywaydb.core.internal.license.VersionPrinter - Flyway Community Edition 9.20.0 by Redgate
2471 [ZAP-daemon] INFO org.flywaydb.core.internal.license.VersionPrinter - See release notes here: https://rd.gt/416ObMi
2471 [ZAP-daemon] INFO org.flywaydb.core.internal.license.VersionPrinter -
2486 [ZAP-daemon] INFO org.flywaydb.core.internal.database.base.BaseDatabaseType - Database: jdbc:hsqldb:file:C:\path\to\project\target\owasp-zap-work\db\permanent (HSQL Database Engine 2.7)
2490 [ZAP-daemon] WARN org.flywaydb.core.internal.database.base.Database - Flyway upgrade recommended: HSQLDB 2.7 is newer than this version of Flyway and support has not been tested. The latest supported version of HSQLDB is 2.6.
2501 [ZAP-daemon] INFO org.flywaydb.core.internal.schemahistory.JdbcTableSchemaHistory - Schema history table "PUBLIC"."flyway_schema_history" does not exist yet
2503 [ZAP-daemon] INFO org.flywaydb.core.internal.command.DbValidate - Successfully validated 1 migration (execution time 00:00.007s)
2508 [ZAP-daemon] INFO org.flywaydb.core.internal.schemahistory.JdbcTableSchemaHistory - Creating Schema History table "PUBLIC"."flyway_schema_history" ...
2532 [ZAP-daemon] INFO org.flywaydb.core.internal.command.DbMigrate - Current version of schema "PUBLIC": << Empty Schema >>
2536 [ZAP-daemon] INFO org.flywaydb.core.internal.command.DbMigrate - Migrating schema "PUBLIC" to version "1 - Create table boast"
2553 [ZAP-daemon] INFO org.flywaydb.core.internal.command.DbMigrate - Successfully applied 1 migration to schema "PUBLIC", now at version v1 (execution time 00:00.002s)
2666 [ZAP-daemon] INFO org.zaproxy.addon.oast.services.callback.CallbackService - Started callback service on 0.0.0.0:64347
2666 [ZAP-daemon] INFO org.zaproxy.zap.extension.quickstart.ExtensionQuickStart - Shh! No check-for-news - silent mode enabled
2666 [ZAP-daemon] INFO org.zaproxy.addon.network.ExtensionNetwork - Creating new root CA certificate.
2949 [ZAP-daemon] INFO org.zaproxy.addon.network.ExtensionNetwork - New root CA certificate created.
2956 [ZAP-daemon] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Shh! No check-for-update - silent mode enabled
3974 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Downloading add-on from: https://github.com/zaproxy/zap-extensions/releases/download/commonlib-v1.28.0/commonlib-release-1.28.0.zap
3975 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Downloading add-on from: https://github.com/zaproxy/zap-extensions/releases/download/pscanrulesAlpha-v43/pscanrulesAlpha-alpha-43.zap
3980 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Downloading add-on from: https://github.com/zaproxy/zap-extensions/releases/download/pscanrulesBeta-v41/pscanrulesBeta-beta-41.zap
3983 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Downloading add-on from: https://github.com/zaproxy/zap-extensions/releases/download/pscanrules-v61/pscanrules-release-61.zap
3983 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Downloading add-on from: https://github.com/zaproxy/zap-extensions/releases/download/pscan-v0.0.1/pscan-alpha-0.0.1.zap
3986 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Downloading add-on from: https://github.com/zaproxy/zap-extensions/releases/download/ascanrulesAlpha-v48/ascanrulesAlpha-alpha-48.zap
3988 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Downloading add-on from: https://github.com/zaproxy/zap-extensions/releases/download/oast-v0.20.0/oast-beta-0.20.0.zap
3988 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Downloading add-on from: https://github.com/zaproxy/zap-extensions/releases/download/database-v0.6.0/database-alpha-0.6.0.zap
3988 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Downloading add-on from: https://github.com/zaproxy/zap-extensions/releases/download/network-v0.18.0/network-beta-0.18.0.zap
3988 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Downloading add-on from: https://github.com/zaproxy/zap-extensions/releases/download/ascanrulesBeta-v56/ascanrulesBeta-beta-56.zap
3991 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Downloading add-on from: https://github.com/zaproxy/zap-extensions/releases/download/ascanrules-v68/ascanrules-release-68.zap
3993 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Downloading add-on from: https://github.com/zaproxy/zap-extensions/releases/download/spider-v0.12.0/spider-release-0.12.0.zap
3995 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Downloading add-on from: https://github.com/zaproxy/zap-extensions/releases/download/selenium-v15.30.0/selenium-release-15.30.0.zap
3995 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Downloading add-on from: https://github.com/zaproxy/zap-extensions/releases/download/spiderAjax-v23.21.0/spiderAjax-release-23.21.0.zap
3998 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Downloading add-on from: https://github.com/zaproxy/zap-extensions/releases/download/reports-v0.33.0/reports-release-0.33.0.zap
3999 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Downloading add-on from: https://github.com/zaproxy/zap-extensions/releases/download/webdriverwindows-v105/webdriverwindows-release-105.zap
52787 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Installing new addon commonlib v1.28.0
53040 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Anti-clickjacking Header" already exists. The rule "org.zaproxy.zap.extension.pscanrules.AntiClickjackingScanRule" will not be loaded.
53040 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.AntiClickjackingScanRule
53040 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Application Error Disclosure" already exists. The rule "org.zaproxy.zap.extension.pscanrules.ApplicationErrorScanRule" will not be loaded.
53040 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.ApplicationErrorScanRule
53040 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Big Redirect Detected (Potential Sensitive Information Leak)" already exists. The rule "org.zaproxy.zap.extension.pscanrules.BigRedirectsScanRule" will not be loaded.
53040 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.BigRedirectsScanRule
53041 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Re-examine Cache-control Directives" already exists. The rule "org.zaproxy.zap.extension.pscanrules.CacheControlScanRule" will not be loaded.
53041 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.CacheControlScanRule
53041 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Charset Mismatch" already exists. The rule "org.zaproxy.zap.extension.pscanrules.CharsetMismatchScanRule" will not be loaded.
53041 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.CharsetMismatchScanRule
53041 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Content Security Policy (CSP) Header Not Set" already exists. The rule "org.zaproxy.zap.extension.pscanrules.ContentSecurityPolicyMissingScanRule" will not be loaded.
53041 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.ContentSecurityPolicyMissingScanRule
53041 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "CSP" already exists. The rule "org.zaproxy.zap.extension.pscanrules.ContentSecurityPolicyScanRule" will not be loaded.
53041 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.ContentSecurityPolicyScanRule
53041 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Content-Type Header Missing" already exists. The rule "org.zaproxy.zap.extension.pscanrules.ContentTypeMissingScanRule" will not be loaded.
53041 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.ContentTypeMissingScanRule
53041 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Cookie No HttpOnly Flag" already exists. The rule "org.zaproxy.zap.extension.pscanrules.CookieHttpOnlyScanRule" will not be loaded.
53041 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.CookieHttpOnlyScanRule
53041 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Loosely Scoped Cookie" already exists. The rule "org.zaproxy.zap.extension.pscanrules.CookieLooselyScopedScanRule" will not be loaded.
53041 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.CookieLooselyScopedScanRule
53041 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Cookie without SameSite Attribute" already exists. The rule "org.zaproxy.zap.extension.pscanrules.CookieSameSiteScanRule" will not be loaded.
53041 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.CookieSameSiteScanRule
53041 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Cookie Without Secure Flag" already exists. The rule "org.zaproxy.zap.extension.pscanrules.CookieSecureFlagScanRule" will not be loaded.
53041 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.CookieSecureFlagScanRule
53042 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Cross-Domain Misconfiguration" already exists. The rule "org.zaproxy.zap.extension.pscanrules.CrossDomainMisconfigurationScanRule" will not be loaded.
53042 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.CrossDomainMisconfigurationScanRule
53042 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Cross-Domain JavaScript Source File Inclusion" already exists. The rule "org.zaproxy.zap.extension.pscanrules.CrossDomainScriptInclusionScanRule" will not be loaded.
53042 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.CrossDomainScriptInclusionScanRule
53042 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Absence of Anti-CSRF Tokens" already exists. The rule "org.zaproxy.zap.extension.pscanrules.CsrfCountermeasuresScanRule" will not be loaded.
53042 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.CsrfCountermeasuresScanRule
53042 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Directory Browsing" already exists. The rule "org.zaproxy.zap.extension.pscanrules.DirectoryBrowsingScanRule" will not be loaded.
53042 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.DirectoryBrowsingScanRule
53042 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Hash Disclosure" already exists. The rule "org.zaproxy.zap.extension.pscanrules.HashDisclosureScanRule" will not be loaded.
53042 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.HashDisclosureScanRule
53042 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Heartbleed OpenSSL Vulnerability (Indicative)" already exists. The rule "org.zaproxy.zap.extension.pscanrules.HeartBleedScanRule" will not be loaded.
53042 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.HeartBleedScanRule
53042 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Private IP Disclosure" already exists. The rule "org.zaproxy.zap.extension.pscanrules.InfoPrivateAddressDisclosureScanRule" will not be loaded.
53042 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.InfoPrivateAddressDisclosureScanRule
53042 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Session ID in URL Rewrite" already exists. The rule "org.zaproxy.zap.extension.pscanrules.InfoSessionIdUrlScanRule" will not be loaded.
53042 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.InfoSessionIdUrlScanRule
53042 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Information Disclosure - Debug Error Messages" already exists. The rule "org.zaproxy.zap.extension.pscanrules.InformationDisclosureDebugErrorsScanRule" will not be loaded.
53042 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.InformationDisclosureDebugErrorsScanRule
53043 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Information Disclosure - Sensitive Information in URL" already exists. The rule "org.zaproxy.zap.extension.pscanrules.InformationDisclosureInUrlScanRule" will not be loaded.
53043 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.InformationDisclosureInUrlScanRule
53043 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Information Disclosure - Sensitive Information in HTTP Referrer Header" already exists. The rule "org.zaproxy.zap.extension.pscanrules.InformationDisclosureReferrerScanRule" will not be loaded.
53043 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.InformationDisclosureReferrerScanRule
53043 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Information Disclosure - Suspicious Comments" already exists. The rule "org.zaproxy.zap.extension.pscanrules.InformationDisclosureSuspiciousCommentsScanRule" will not be loaded.
53043 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.InformationDisclosureSuspiciousCommentsScanRule
53043 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Weak Authentication Method" already exists. The rule "org.zaproxy.zap.extension.pscanrules.InsecureAuthenticationScanRule" will not be loaded.
53043 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.InsecureAuthenticationScanRule
53043 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "HTTP to HTTPS Insecure Transition in Form Post" already exists. The rule "org.zaproxy.zap.extension.pscanrules.InsecureFormLoadScanRule" will not be loaded.
53043 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.InsecureFormLoadScanRule
53043 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "HTTPS to HTTP Insecure Transition in Form Post" already exists. The rule "org.zaproxy.zap.extension.pscanrules.InsecureFormPostScanRule" will not be loaded.
53043 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.InsecureFormPostScanRule
53043 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Insecure JSF ViewState" already exists. The rule "org.zaproxy.zap.extension.pscanrules.InsecureJsfViewStatePassiveScanRule" will not be loaded.
53043 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.InsecureJsfViewStatePassiveScanRule
53043 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Reverse Tabnabbing" already exists. The rule "org.zaproxy.zap.extension.pscanrules.LinkTargetScanRule" will not be loaded.
53043 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.LinkTargetScanRule
53043 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Secure Pages Include Mixed Content" already exists. The rule "org.zaproxy.zap.extension.pscanrules.MixedContentScanRule" will not be loaded.
53043 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.MixedContentScanRule
53043 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Modern Web Application" already exists. The rule "org.zaproxy.zap.extension.pscanrules.ModernAppDetectionScanRule" will not be loaded.
53043 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.ModernAppDetectionScanRule
53043 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "PII Disclosure" already exists. The rule "org.zaproxy.zap.extension.pscanrules.PiiScanRule" will not be loaded.
53043 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.PiiScanRule
53043 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Retrieved from Cache" already exists. The rule "org.zaproxy.zap.extension.pscanrules.RetrievedFromCacheScanRule" will not be loaded.
53043 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.RetrievedFromCacheScanRule
53043 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "HTTP Server Response Header" already exists. The rule "org.zaproxy.zap.extension.pscanrules.ServerHeaderInfoLeakScanRule" will not be loaded.
53043 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.ServerHeaderInfoLeakScanRule
53043 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Strict-Transport-Security Header" already exists. The rule "org.zaproxy.zap.extension.pscanrules.StrictTransportSecurityScanRule" will not be loaded.
53043 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.StrictTransportSecurityScanRule
53043 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Timestamp Disclosure" already exists. The rule "org.zaproxy.zap.extension.pscanrules.TimestampDisclosureScanRule" will not be loaded.
53044 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.TimestampDisclosureScanRule
53044 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "User Controllable Charset" already exists. The rule "org.zaproxy.zap.extension.pscanrules.UserControlledCharsetScanRule" will not be loaded.
53044 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.UserControlledCharsetScanRule
53044 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Cookie Poisoning" already exists. The rule "org.zaproxy.zap.extension.pscanrules.UserControlledCookieScanRule" will not be loaded.
53044 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.UserControlledCookieScanRule
53044 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "User Controllable HTML Element Attribute (Potential XSS)" already exists. The rule "org.zaproxy.zap.extension.pscanrules.UserControlledHTMLAttributesScanRule" will not be loaded.
53044 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.UserControlledHTMLAttributesScanRule
53044 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "User Controllable JavaScript Event (XSS)" already exists. The rule "org.zaproxy.zap.extension.pscanrules.UserControlledJavascriptEventScanRule" will not be loaded.
53044 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.UserControlledJavascriptEventScanRule
53044 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Open Redirect" already exists. The rule "org.zaproxy.zap.extension.pscanrules.UserControlledOpenRedirectScanRule" will not be loaded.
53044 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.UserControlledOpenRedirectScanRule
53044 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Username Hash Found" already exists. The rule "org.zaproxy.zap.extension.pscanrules.UsernameIdorScanRule" will not be loaded.
53044 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.UsernameIdorScanRule
53044 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Viewstate" already exists. The rule "org.zaproxy.zap.extension.pscanrules.ViewstateScanRule" will not be loaded.
53044 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.ViewstateScanRule
53044 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "X-AspNet-Version Response Header" already exists. The rule "org.zaproxy.zap.extension.pscanrules.XAspNetVersionScanRule" will not be loaded.
53044 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.XAspNetVersionScanRule
53045 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "X-Backend-Server Header Information Leak" already exists. The rule "org.zaproxy.zap.extension.pscanrules.XBackendServerInformationLeakScanRule" will not be loaded.
53045 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.XBackendServerInformationLeakScanRule
53045 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "X-ChromeLogger-Data (XCOLD) Header Information Leak" already exists. The rule "org.zaproxy.zap.extension.pscanrules.XChromeLoggerDataInfoLeakScanRule" will not be loaded.
53045 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.XChromeLoggerDataInfoLeakScanRule
53045 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "X-Content-Type-Options Header Missing" already exists. The rule "org.zaproxy.zap.extension.pscanrules.XContentTypeOptionsScanRule" will not be loaded.
53045 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.XContentTypeOptionsScanRule
53045 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "X-Debug-Token Information Leak" already exists. The rule "org.zaproxy.zap.extension.pscanrules.XDebugTokenScanRule" will not be loaded.
53045 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.XDebugTokenScanRule
53045 [ZAP-DownloadInstaller] WARN org.zaproxy.zap.extension.pscan.PassiveScannerList - A scan rule with the name "Server Leaks Information via "X-Powered-By" HTTP Response Header Field(s)" already exists. The rule "org.zaproxy.zap.extension.pscanrules.XPoweredByHeaderInfoLeakScanRule" will not be loaded.
53045 [ZAP-DownloadInstaller] ERROR org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Failed to install pscanrule: org.zaproxy.zap.extension.pscanrules.XPoweredByHeaderInfoLeakScanRule
53086 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.quickstart.ExtensionQuickStart - Shh! No check-for-news - silent mode enabled
53098 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Finished installing new addon commonlib v1.28.0
53100 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Installing new addon pscanrulesAlpha v43.0.0
53113 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Base64 Disclosure
53113 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: An example passive scan rule which loads data from a file.
53113 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Example Passive Scan Rule: Denial of Service
53113 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Fetch Metadata Request Headers
53113 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Full Path Disclosure
53115 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Finished installing new addon pscanrulesAlpha v43.0.0
53116 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Installing new addon pscanrulesBeta v41.0.0
53131 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Content Cacheability
53131 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: In Page Banner Information Leak
53131 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Dangerous JS Functions
53131 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Java Serialization Object
53131 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Permissions Policy Header Not Set
53131 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: HTTP Parameter Override
53131 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Insufficient Site Isolation Against Spectre Vulnerability
53131 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Source Code Disclosure
53131 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Sub Resource Integrity Attribute Missing
53134 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Finished installing new addon pscanrulesBeta v41.0.0
53143 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Installing new addon pscanrules v61.0.0
53143 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Finished installing new addon pscanrules v61.0.0
53145 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Installing new addon pscan v0.0.1
53172 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Anti-clickjacking Header
53172 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Application Error Disclosure
53172 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Big Redirect Detected (Potential Sensitive Information Leak)
53172 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Re-examine Cache-control Directives
53172 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Charset Mismatch
53172 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Content Security Policy (CSP) Header Not Set
53172 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: CSP
53172 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Content-Type Header Missing
53172 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Cookie No HttpOnly Flag
53172 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Loosely Scoped Cookie
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Cookie without SameSite Attribute
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Cookie Without Secure Flag
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Cross-Domain Misconfiguration
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Cross-Domain JavaScript Source File Inclusion
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Absence of Anti-CSRF Tokens
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Directory Browsing
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Hash Disclosure
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Heartbleed OpenSSL Vulnerability (Indicative)
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Private IP Disclosure
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Session ID in URL Rewrite
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Information Disclosure - Debug Error Messages
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Information Disclosure - Sensitive Information in URL
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Information Disclosure - Sensitive Information in HTTP Referrer Header
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Information Disclosure - Suspicious Comments
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Weak Authentication Method
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: HTTP to HTTPS Insecure Transition in Form Post
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: HTTPS to HTTP Insecure Transition in Form Post
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Insecure JSF ViewState
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Reverse Tabnabbing
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Secure Pages Include Mixed Content
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Modern Web Application
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: PII Disclosure
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Script Served From Malicious Domain (polyfill)
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Retrieved from Cache
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: HTTP Server Response Header
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Strict-Transport-Security Header
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Timestamp Disclosure
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: User Controllable Charset
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Cookie Poisoning
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: User Controllable HTML Element Attribute (Potential XSS)
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: User Controllable JavaScript Event (XSS)
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Open Redirect
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Username Hash Found
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Viewstate
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: X-AspNet-Version Response Header
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: X-Backend-Server Header Information Leak
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: X-ChromeLogger-Data (XCOLD) Header Information Leak
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: X-Content-Type-Options Header Missing
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: X-Debug-Token Information Leak
53173 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Server Leaks Information via "X-Powered-By" HTTP Response Header Field(s)
53175 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Finished installing new addon pscan v0.0.1
53177 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Installing new addon ascanrulesAlpha v48.0.0
53189 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Finished installing new addon ascanrulesAlpha v48.0.0
53216 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Installing new addon oast v0.20.0
53216 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Finished installing new addon oast v0.20.0
53233 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Installing new addon database v0.6.0
53352 [ZAP-DownloadInstaller] INFO org.zaproxy.addon.oast.services.boast.BoastParam - Updating configurations from v1 to v2
53782 [ZAP-DownloadInstaller] INFO org.flywaydb.core.internal.license.VersionPrinter - Flyway Community Edition 9.22.3 by Redgate
53783 [ZAP-DownloadInstaller] INFO org.flywaydb.core.internal.license.VersionPrinter - See release notes here: https://rd.gt/416ObMi
53783 [ZAP-DownloadInstaller] INFO org.flywaydb.core.internal.license.VersionPrinter -
53792 [ZAP-DownloadInstaller] INFO org.flywaydb.core.FlywayExecutor - Database: jdbc:hsqldb:file:C:\path\to\project\target\owasp-zap-work\db\permanent (HSQL Database Engine 2.7)
53808 [ZAP-DownloadInstaller] INFO org.flywaydb.core.internal.command.DbValidate - Successfully validated 2 migrations (execution time 00:00.009s)
53812 [ZAP-DownloadInstaller] INFO org.flywaydb.core.internal.command.DbMigrate - Current version of schema "PUBLIC": 1
53820 [ZAP-DownloadInstaller] INFO org.flywaydb.core.internal.command.DbMigrate - Migrating schema "PUBLIC" to version "2 - Create table alert"
53828 [ZAP-DownloadInstaller] INFO org.flywaydb.core.internal.command.DbMigrate - Successfully applied 1 migration to schema "PUBLIC", now at version v2 (execution time 00:00.004s)
53846 [ZAP-DownloadInstaller] INFO org.zaproxy.addon.oast.services.callback.CallbackService - Started callback service on 0.0.0.0:65499
53885 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Finished installing new addon database v0.6.0
53892 [ZAP-DownloadInstaller] INFO org.parosproxy.paros.network.SSLConnector - Reading supported SSL/TLS protocols...
53892 [ZAP-DownloadInstaller] INFO org.parosproxy.paros.network.SSLConnector - Using a SSLEngine...
53894 [ZAP-DownloadInstaller] INFO org.parosproxy.paros.network.SSLConnector - Done reading supported SSL/TLS protocols: [SSLv2Hello, SSLv3, TLSv1, TLSv1.1, TLSv1.2, TLSv1.3]
58100 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Installing new addon network v0.18.0
58178 [ZAP-DownloadInstaller] INFO org.zaproxy.addon.network.internal.TlsUtils - Using supported SSL/TLS protocols: [TLSv1.2, TLSv1.3]
58357 [ZAP-DownloadInstaller] INFO org.zaproxy.addon.network.ConnectionOptions - Unsafe SSL/TLS renegotiation disabled.
58452 [ZAP-DownloadInstaller] INFO org.zaproxy.addon.network.ExtensionNetwork - ZAP is now listening on localhost:8080
58459 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.quickstart.ExtensionQuickStart - Shh! No check-for-news - silent mode enabled
58696 [ZAP-DownloadInstaller] INFO org.flywaydb.core.FlywayExecutor - Database: jdbc:hsqldb:file:C:\path\to\project\target\owasp-zap-work\db\permanent (HSQL Database Engine 2.7)
58699 [ZAP-DownloadInstaller] INFO org.flywaydb.core.internal.command.DbValidate - Successfully validated 2 migrations (execution time 00:00.002s)
58701 [ZAP-DownloadInstaller] INFO org.flywaydb.core.internal.command.DbMigrate - Current version of schema "PUBLIC": 2
58702 [ZAP-DownloadInstaller] INFO org.flywaydb.core.internal.command.DbMigrate - Schema "PUBLIC" is up to date. No migration necessary.
58708 [ZAP-DownloadInstaller] INFO org.zaproxy.addon.oast.services.callback.CallbackService - Started callback service on 0.0.0.0:65505
58735 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Finished installing new addon network v0.18.0
58737 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Installing new addon ascanrulesBeta v56.0.0
58754 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Finished installing new addon ascanrulesBeta v56.0.0
58759 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Installing new addon ascanrules v68.0.0
58785 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Finished installing new addon ascanrules v68.0.0
58789 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Installing new addon spider v0.12.0
58805 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Finished installing new addon spider v0.12.0
58807 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Installing new addon selenium v15.30.0
59003 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Finished installing new addon selenium v15.30.0
59005 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Installing new addon spiderAjax v23.21.0
59031 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Finished installing new addon spiderAjax v23.21.0
59319 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Installing new addon reports v0.33.0
59369 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.quickstart.ExtensionQuickStart - Shh! No check-for-news - silent mode enabled
59370 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Finished installing new addon reports v0.33.0
59371 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Installing new addon webdriverwindows v105.0.0
59664 [ZAP-DownloadInstaller] INFO org.zaproxy.zap.extension.autoupdate.ExtensionAutoUpdate - Finished installing new addon webdriverwindows v105.0.0
59672 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Add-on downloaded to: C:\path\to\project\target\owasp-zap-work\plugin\pscanrulesBeta-beta-41.zap
59672 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Add-on downloaded to: C:\path\to\project\target\owasp-zap-work\plugin\pscan-alpha-0.0.1.zap
59672 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Add-on downloaded to: C:\path\to\project\target\owasp-zap-work\plugin\ascanrulesAlpha-alpha-48.zap
59672 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Add-on downloaded to: C:\path\to\project\target\owasp-zap-work\plugin\pscanrulesAlpha-alpha-43.zap
59672 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Add-on downloaded to: C:\path\to\project\target\owasp-zap-work\plugin\ascanrulesBeta-beta-56.zap
59672 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Add-on downloaded to: C:\path\to\project\target\owasp-zap-work\plugin\spider-release-0.12.0.zap
59672 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Add-on downloaded to: C:\path\to\project\target\owasp-zap-work\plugin\oast-beta-0.20.0.zap
59672 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Add-on downloaded to: C:\path\to\project\target\owasp-zap-work\plugin\pscanrules-release-61.zap
59672 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Add-on downloaded to: C:\path\to\project\target\owasp-zap-work\plugin\ascanrules-release-68.zap
59672 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Add-on downloaded to: C:\path\to\project\target\owasp-zap-work\plugin\spiderAjax-release-23.21.0.zap
59673 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Add-on downloaded to: C:\path\to\project\target\owasp-zap-work\plugin\reports-release-0.33.0.zap
59673 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Add-on downloaded to: C:\path\to\project\target\owasp-zap-work\plugin\commonlib-release-1.28.0.zap
59673 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Add-on downloaded to: C:\path\to\project\target\owasp-zap-work\plugin\webdriverwindows-release-105.zap
59673 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Add-on downloaded to: C:\path\to\project\target\owasp-zap-work\plugin\database-alpha-0.6.0.zap
59673 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Add-on downloaded to: C:\path\to\project\target\owasp-zap-work\plugin\network-beta-0.18.0.zap
59673 [ZAP-daemon] INFO org.parosproxy.paros.CommandLine - Add-on downloaded to: C:\path\to\project\target\owasp-zap-work\plugin\selenium-release-15.30.0.zap
59673 [ZAP-daemon] INFO org.zaproxy.addon.callhome.ExtensionCallHome - Shh! Silent mode or telemetry turned off
59678 [ZAP-daemon] INFO org.zaproxy.addon.network.ExtensionNetwork - ZAP is now listening on localhost:8090
Describe the bug:
Problem: When calling ZAP 2.15 via the zap-maven-plugin, as soon as a new commonlib (> commonlib-release-1.25.0.zap which is contained in the download bundle) is available and installed, for each of the 49 passive rules the following warning & error appears in zap.log (full log below):
Notes:
Workaround: After looking at the log I saw that the exact same scanrules are already loaded in zap.log a few seconds before, e.g.
[ZAP-daemon] INFO org.zaproxy.zap.extension.pscan.ExtensionPassiveScan - Loaded passive scan rule: Anti-clickjacking Header
When I removed the "pscanrules-release-58.zap" from the ZAP Installation directory, this earlier loading does not happen and according to zap.log, ZAP successfully downloads and installs all latest extensions, in particularSteps to reproduce the behavior:
<zapOptions>-daemon -silent -config start.checkForUpdates=false -config api.disablekey=true -config network.connection.httpProxy.enabled=true -config network.connection.httpProxy.host=${owasp.maven.proxy.host} -config network.connection.httpProxy.port=${owasp.maven.proxy.port} -config network.connection.httpProxy.exclusions.exclusion.host=${owaspZapTargetHost} -config network.connection.defaultUserAgent="${owaspZapDefaultUserAgent}" -dir ${owaspZapWork} -addoninstall pscanrulesAlpha -addoninstall pscanrulesBeta -addoninstall pscanrules -addoninstall ascanrulesAlpha -addoninstall ascanrulesBeta -addoninstall ascanrules -addoninstall spider -addoninstall spiderAjax -addoninstall reports -addoninstall webdriverwindows<zapOptions>
mvn clean verify
Expected behavior:
ZAP should download and install all used extensions/plugins in their most up-to-date version without throwing any errors. In this case it seems that the passive scanrules are initialized twice.
Software versions:
ZAP 2.15 (Core Cross Platform Package)
Screenshots:
No response
Errors from the zap.log file:
Basically as described, this time with more details:
Additional context:
No response
Would you like to help fix this issue?