URL Disclosure Vulnerability in Burp Suite by PortSwigger
CVE-2022-35406

4.3MEDIUM

Key Information:

Vendor
CVE Published:
8 July 2022

What is CVE-2022-35406?

A URL disclosure issue was found in Burp Suite that affects versions prior to 2022.6. When users interact with crafted responses in the Repeater or Intruder tools, these responses may be misinterpreted, leading to potential redirects that could disclose sensitive information. Users are advised to be cautious while handling responses and ensure they're using the updated version to mitigate this risk.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.