Skip to content

Releases: factionsecurity/faction

1.3.25

08 Oct 06:04

Choose a tag to compare

Minor bugfixes related to registering users.

1.3.22

03 Oct 06:43

Choose a tag to compare

🚨Breaking Changes🚨

This versions after 1.3.20 made an update to how password hashing is done. All of your users on older versions of faction will need to reset their passwords after updating.

Bug fixes

Fixed issue where CVSS scores didn't automatically populate from default vulnerabilities

Enhancements

Updated CSS around select boxes

1.3.21

26 Sep 23:40

Choose a tag to compare

🚨Breaking Changes🚨

This versions after 1.3.20 made an update to how password hashing is done. All of your users on older versions of faction will need to reset their passwords after updating.

Bug fixes

fixed an XSS issue reported by @GPUkiller #71
fixed api issue reported by @ptrac3 #68

Updates

Adding SSL for mongo and options to allow mongo to work with documentDB in aws.

1.3.20

26 Sep 19:49

Choose a tag to compare

🚨Breaking Changes🚨

This version makes an update to how password hashing is done. All of your users on older versions of faction will need to reset their passwords after updating.

Bug fixes

fixed an XSS issue reported by @GPUkiller #71

Updates

Adding SSL for mongo and options to allow mongo to work with documentDB in aws.

1.3.8

09 Aug 23:31

Choose a tag to compare

This release brings many new features and improved workflows:

Moved Assessment notes to its on tab where you can have notebooks with many pages.
Remediation Workflow has changed.
When you open a vuln it opens a new page with an improved interface for managing issues.
Generate Retest reports and download original assessment reports from within the Remediation interface.
When Retests are complete a Retest report is sent to the assessor's Notification Queue.
Vulnerabilities and Verifications now have tags to make it easy to see the status
Updated variables for retest reports.
New Text editors with default Markdown.
Bugfixes:

Fixed issue where vulnerability custom variables were not getting updated
Fixed an issue where reports would not generate if the was a text box in the body of the report.
Updated docx4j that fixed an issue where sometimes reports would display the 'corrupted file' warning in Word .

1.3.0

08 Aug 23:35

Choose a tag to compare

This release brings many new features and improved workflows:

  1. Moved Assessment notes to its on tab where you can have notebooks with many pages.
  2. Remediation Workflow has changed.
    1. When you open a vuln it opens a new page with an improved interface for managing issues.
    2. Generate Retest reports and download original assessment reports from within the Remediation interface.
    3. When Retests are complete a Retest report is sent to the assessor's Notification Queue.
    4. Vulnerabilities and Verifications now have tags to make it easy to see the status
  3. Updated variables for retest reports.
  4. New Text editors with default Markdown.

Bugfixes:

  1. Fixed issue where vulnerability custom variables were not getting updated
  2. Fixed an issue where reports would not generate if the was a text box in the body of the report.
  3. Updated docx4j that fixed an issue where sometimes reports would display the 'corrupted file' warning in Word .

1.2.6

18 Jun 04:43

Choose a tag to compare

  • Fixes issues in uploading assessment CSV
  • Fixes issue where vuln details don't get replaced when adding a new vuln
  • Fixes UI bugs when deleting an assessment

1.2.5

16 Apr 18:22

Choose a tag to compare

Bugfix:

  • Introduced an issue that broke the text editor in scheduling.
  • Bad escape in remediation searching
  • Filters not working in remediation search

1.2.4

15 Apr 22:53

Choose a tag to compare

Bugfix

  • "Undo" history captured details from every vulnerability selected causing "undo" to show incorrect history.
  • Fix issues with markdown that would format tables incorrectly

Added Features

  • Text editors now have a code view.

1.2.3

01 Apr 13:49

Choose a tag to compare

Bugfix

  • Unable to change severities with native vulnerability rankings