The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

2 open jdks

Rummy | Last updated: Jul 20, 2023 04:55PM UTC

Hi, I do notice that there are 2 Open JDK install folders as below. sudo /app/./burpsuite_enterprise/jre/bin/java -version openjdk version "17.0.4" 2022-07-19 LTS OpenJDK Runtime Environment Zulu17.36+13-CA (build 17.0.4+8-LTS) OpenJDK 64-Bit Server VM Zulu17.36+13-CA (build 17.0.4+8-LTS, mixed mode, sharing) sudo /app/./burpsuite_enterprise/jres/17.0.7/bin/java -version openjdk version "17.0.7" 2023-04-18 LTS OpenJDK Runtime Environment Zulu17.42+19-CA (build 17.0.7+7-LTS) OpenJDK 64-Bit Server VM Zulu17.42+19-CA (build 17.0.7+7-LTS, mixed mode, sharing) We are having vulnerability issue with 17.0.4 version. And i see below process running on this 17.0.4 version ps -ef | grep java | grep '\/jre\/' burpsui+ 2338 2142 0 May18 ? 00:48:58 /app/burpsuite_enterprise/jre/bin/java -classpath /app/burpsuite_enterprise/.install4j/i4jruntime.jar:/app/burpsuite_enterprise/.install4j/launcher7048aa1a.jar:/app/burpsuite_enterprise/supervisor/* install4j.net.portswigger.Supervisor_burpsuiteenterpriseedition_agent start enterpriseAgent/.supervise burpsui+ 2339 2120 0 May18 ? 00:49:16 /app/burpsuite_enterprise/jre/bin/java -classpath /app/burpsuite_enterprise/.install4j/i4jruntime.jar:/app/burpsuite_enterprise/.install4j/launchered14aa48.jar:/app/burpsuite_enterprise/supervisor/* install4j.net.portswigger.Supervisor_burpsuiteenterpriseedition_enterpriseserver start enterpriseServer/.supervise burpsui+ 2357 2112 0 May18 ? 00:48:59 /app/burpsuite_enterprise/jre/bin/java -classpath /app/burpsuite_enterprise/.install4j/i4jruntime.jar:/app/burpsuite_enterprise/.install4j/launcher2ff15a18.jar:/app/burpsuite_enterprise/supervisor/* install4j.net.portswigger.Supervisor_burpsuiteenterpriseedition_webserver start webServer/.supervise Just want to check if it is safe to remove jre folder which has 17.0.4 version as it is showing up in our vulnerability scans? Thanks!

Josh, PortSwigger Agent | Last updated: Jul 21, 2023 08:16AM UTC