First published: Fri Jul 08 2022(Updated: )
A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Burp Suite | <2022.6 | |
Burp Suite | <2022.6 |
https://portswigger.net/burp/releases/professional-community-2022-6?requestededition=professional
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-35406 is considered low, as it primarily involves a URL disclosure issue.
To fix CVE-2022-35406, update to Burp Suite version 2022.6 or later.
CVE-2022-35406 is caused by the incorrect handling of crafted responses that may be misinterpreted as redirects.
CVE-2022-35406 affects users of Burp Suite versions prior to 2022.6, including both Community and Professional editions.
While CVE-2022-35406 does not lead to direct exploitation risks, it may expose sensitive URLs to unauthorized users.