Burp Suite User Forum

Create new post

Confidential/sensitive information accessible for non-legitimate users

BOURASS | Last updated: Mar 03, 2021 04:48PM UTC

Hello, During a POC we are running using BurpSuite Enterprise web application scanner, we encountered an issue (not much a bug, but more a security weakness) : as it is possible to provide credentials for authenticated scans in the "Scan Configuration" feature, any user that has access rights on the scan configurations can download all scan configurations and access credentials within, which are in plain text. Hope you can help us with this issue. Thank you. Taha BOURASS

Michelle, PortSwigger Agent | Last updated: Mar 04, 2021 05:11PM UTC

Thanks for the feedback. Can I just confirm that this is when details for platform authentication are being used? If you could restrict which users could see those scan configurations, would that be an acceptable option for you?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.