This release lets you apply triage decisions to matching issues, adds issue retests to the GraphQL API, makes scans faster, and fixes a number of bugs.
Apply triage decisions to matching issues with issue management rules
When you mark an issue as a false positive or accepted risk, or change its severity, you can now choose how widely to apply the change:
- This issue only
- This issue type at this URL
- This issue type anywhere on this site
Burp Suite DAST updates the matching issues on the site straight away and creates an issue management rule. Matching issues found in future scans are then handled the same way, so you don't need to triage them again.
To view or delete your rules, go to Settings > Issue management rules. Deleting a rule doesn't change issues it has already updated.
Verify fixes automatically with retests from the API
You can now trigger issue retests through the GraphQL API, so you can confirm that vulnerabilities are fixed without running a full scan or opening Burp Suite DAST.
For more information, see the Burp Suite DAST GraphQL Schema.
Faster scans that use less disk space
We made performance improvements to the scanner. Scans now run faster and take up less disk space.
Bug fixes
We've fixed the following bugs:
- Jira integration rules that use the same custom field no longer show or save each other's values.
- OpenAPI definitions with paths written without a leading slash are now scanned at the declared path, instead of the server root.
- OpenAPI definitions with very large numeric bounds no longer cause scans to fail.
- SOAP services defined by a WSDL with a templated or unusable service address are now scanned, instead of yielding no operations.
- Scan coverage is improved on HTTP/2 sites: requests interrupted when the server closes a connection are now retried.
- The count on the All issues tab on the home page now matches the filters you have applied.