The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

log4j2 vulnerability - are burpesuite products affected?

Muhammad | Last updated: Dec 13, 2021 02:53PM UTC

Hi, Could you please clarify if burpesuite products are affected by newly discovered log4j vulnerability. More info on the vulnerability below: https://www.microsoft.com/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation/ Would appreciate if you could please assist.

Uthman, PortSwigger Agent | Last updated: Dec 13, 2021 04:01PM UTC

Hi Muhammad, We utilize a custom-built JDK and I can confirm we don’t use log4j for logging. (we use slf4j). It is still included as a transitive dependency, so as a precautionary measure, we are in the process of excluding the core library from the dependencies altogether. We will be releasing this fix imminently, but I would be happy to confirm via update once complete. To clarify, the above is in relation to Burp Suite Enterprise since Burp Suite Professional does not use log4j at all (excluding third-party extensions on the BApp Store - which we are in the process of reviewing and do not affect Pro itself).

Muhammad | Last updated: Dec 15, 2021 12:04PM UTC

Hi Uthman, Thanks for your reply. Can you confirm if we would be able to find the vulnerability log4j while scanning the services? Best regards,

Uthman, PortSwigger Agent | Last updated: Dec 15, 2021 03:17PM UTC

Muhammad | Last updated: Dec 15, 2021 04:52PM UTC

Hi, we are using Burpe Suite professional. Now we need to scan some services (websites) on the servers if we have fixed the issue or not. There is no point for me to upgrade Enterprise version. And can you please explain what do you mean by scanning the entire installation directory? Thank you

Uthman, PortSwigger Agent | Last updated: Dec 16, 2021 08:12AM UTC