---
title: "OWASP Zap"
description: "This helps you discover vulnerabilities in web applications"
url: https://whitespots.io/docs/whitespots-wiki/appsec-portal/features/scanners/scanner-description/web-scanners/owasp-zap
slug: whitespots-wiki/appsec-portal/features/scanners/scanner-description/web-scanners/owasp-zap
publish_date: 2025-11-13T18:00:34.000Z
last_modified: 2025-11-13T18:00:34.000Z
---

# OWASP Zap

# OWASP Zap

**AppSec Portal Importer Name**: GitLab OWASP Zap

[GitLab OWASP Zap](https://docs.gitlab.com/ee/user/application\_security/dast/proxy-based.html) is a penetration testing and vulnerability detection tool for **web applications**. It offers capabilities to scan web applications for vulnerabilities like **SQL injection**, **cross-site scripting (XSS)**, and more. OWASP Zap helps developers explore web application security and safeguard against known attacks.

#### Curl example

{% code overflow="wrap" %}
```
curl -X POST localhost/api/v1/scan/import/ -H "Authorization: Token a75bb26171cf391671e67b128bfc8ae1c779ff7b" -H "Content-Type: multipart/form-data" -F "file=@./gl-dast-report.json" -F "product_name=Product1" -F "product_type=Application" -F "scanner_name=GitLab OWASP Zap" -F "branch=dev" 
```
{% endcode %}

In this command, the following parameters are used:

1. `-X POST`: specifies the HTTP method to be used (in this case, POST)
2. `-H "Authorization: Token <authorization_token>"`: specifies the [**authorization token**](https://whitespots.io/docs/whitespots-wiki/appsec-portal/features/scanners/importing-reports-from-scanners-to-appsec-portal#authorization-token) obtained from AppSec Portal.
3. `-H "Content-Type: multipart/form-data"`: specifies the content type of the request.
4. `-F "file=@<report_file_path>"`: specifies the **path to the report file** generated by the scanner.
5. `-F "product_name=<product_name>"`: specifies the **name of the product** being scanned.
6. `-F "product_type=<product_type>"`: specifies the **type of the product** being scanned.
7. `-F "scanner_name=<scanner_name>"`: specifies the **name of the scanner** used to generate the report (GitLab OWASP Zap)
8. `-F "branch=<branch_name>"`: (_optional_) specifies the name of the branch in the source code repository (if applicable) This parameter is particularly useful when you want to associate the scan results with a specific branch in your repository. If not provided, the scan will be associated with the default branch

---

## Navigation

- Location: [Docs](https://whitespots.io/docs) > [Whitespots Wiki](https://whitespots.io/docs/whitespots-wiki) > [AppSec Portal](https://whitespots.io/docs/whitespots-wiki/appsec-portal) > [🎯 Features](https://whitespots.io/docs/whitespots-wiki/appsec-portal/features) > [🔬 Scanners](https://whitespots.io/docs/whitespots-wiki/appsec-portal/features/scanners) > [Scanner description](https://whitespots.io/docs/whitespots-wiki/appsec-portal/features/scanners/scanner-description) > [Web Scanners](https://whitespots.io/docs/whitespots-wiki/appsec-portal/features/scanners/scanner-description/web-scanners)
- Previous: [Burp Enterprise Scan](https://whitespots.io/docs/whitespots-wiki/appsec-portal/features/scanners/scanner-description/web-scanners/burp-enterprise-scan)
- Next: [Security Metrics](https://whitespots.io/docs/whitespots-wiki/appsec-portal/features/security-metrics)
