Burp Suite User Forum

Create new post

Chromium 0day vulnerability impact scope

ZDY | Last updated: Apr 19, 2021 03:54AM UTC

Hello, I would like to know whether burpsuite_pro_v2020.2.jar uses chromium or chrome as a component, in order to evaluate whether this version of burpsuite is affected by the recent 2 remote arbitrary code execution 0day vulnerabilities.

Uthman, PortSwigger Agent | Last updated: Apr 19, 2021 01:17PM UTC

Hi, It does, yes. Chromium version 80.0.3987.122 is used in 2020.2 but this is usually patched with each update. The latest version of Burp (2021.3.3) uses Chromium 89.0.4389.128.

ZDY | Last updated: Apr 20, 2021 09:31AM UTC

Burp suite (2021.3.3) needs to upgrade Java on my PC, so I don't want to upgrade. Which lower versions of Burp suite do not use Chromium

Uthman, PortSwigger Agent | Last updated: Apr 20, 2021 10:47AM UTC

You would need to use a version below 2020.1, but I would not personally recommend doing this. You should keep up-to-date to ensure you can make the most out of new features and security updates.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.