The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

False Positives For Dependency confusion because of extra character...

Steven | Last updated: May 13, 2023 03:01PM UTC

To Whom it may concern, When opening a package-lock.json file in the browser with burp running, BurpSuite falsly identifies a HIGH Vulnerabilty know as Dependency Confusion every time... This is occuring because the "{" character is being added in the query to npm to identify the package name. This issue can be fixed by removing the "{" from the search query to npm... I abosoluty suck at coding which is why i cant do it myself and am asking for help... Thank you for your time and hope this issue is fixed soon thank you...

Hannah, PortSwigger Agent | Last updated: May 15, 2023 04:17PM UTC