CVE-2022-35406: Medium severity PortSwigger Burp Suite vulnerability
Published Jul 8, 2022
·Updated
A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect.
Affected Software
2 affected components
PortSwigger Burp Suite<2022.6
PortSwigger Burp Suite<2022.6
Remediation
Event History
Jul 8, 2022
CVE Published
via MITRE·03:33 PM
Data Sourced
via MITRE·03:33 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-35406?
The severity of CVE-2022-35406 is considered low, as it primarily involves a URL disclosure issue.
2
How do I fix CVE-2022-35406?
To fix CVE-2022-35406, update to Burp Suite version 2022.6 or later.
3
What causes CVE-2022-35406 in Burp Suite?
CVE-2022-35406 is caused by the incorrect handling of crafted responses that may be misinterpreted as redirects.
4
Who is affected by CVE-2022-35406?
CVE-2022-35406 affects users of Burp Suite versions prior to 2022.6, including both Community and Professional editions.
5
Can CVE-2022-35406 lead to security risks?
While CVE-2022-35406 does not lead to direct exploitation risks, it may expose sensitive URLs to unauthorized users.