Burp Suite User Forum

Create new post

Enterprise REST API False Positives

Bailey, | Last updated: Feb 04, 2020 07:09PM UTC

When a finding is marked as a False Positive in the web ui, it is not updated in the API output. It is understandable for scans already executed but the next scan of the application yields a finding marked as False Positive in the web ui but then it is still listed as a valid finding in the API output. Can the API output be updated to respect the web ui findings? Also, is there a switch for the scan progress API task to include/exclude False Positives like there is in report extract?

Hannah, PortSwigger Agent | Last updated: Feb 05, 2020 08:25AM UTC

This is not currently possible, as the current API outputs issues as soon as it finds them. However, as seen in our roadmap (https://portswigger.net/blog/burp-suite-roadmap-for-2020), we are working on improving our API. Therefore, once the new API is out, it should be possible for false positives to be marked in the API as well as the web UI.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.