Burp Suite User Forum

Create new post

CVE-2022-42889 impact on Burp

SecTer | Last updated: Oct 21, 2022 09:27AM UTC

Above CVE is about a vulnerability in Apache Commons Text which is fixed in version 1.10. However, Burp Enterprise uses version 1.7 of this library. ``` ./burp/enterpriseServer/2022.9-10760/lib/commons-text-1.7.jar ./burp/databaseServer/2022.9-10760/lib/commons-text-1.7.jar ``` When will an update be available?

Alex, PortSwigger Agent | Last updated: Oct 21, 2022 10:05AM UTC

Hi, Thanks for your post. We do have a pending development ticket to update this library, but currently, I cannot offer an ETA on its release. To note, this dependency is only utilized in the use of the database transfer tool, which is used to migrate from H2 to an external database. If you have no intention of using the transfer tool you can safely delete the commons-text-1.7.jar files to prevent the flag. Best regards,

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.