Burp Suite User Forum

Create new post

Queries related to the Openssl vulnerability

Tomoya | Last updated: Sep 30, 2021 06:16AM UTC

We become indebted to. My name is Toru Morokata and i work at Hitachi, Ltd. I'd like to ask about "Burp Suite Professional Edition". A vulnerability named CVE-2021-3711 and CVE-2021-3712 has been discovered about OpenSSL. I am investigating whether the applications I am using are affected by the vulnerability. Does "Burp Suite Professional Edition" use OpenSSL? If "Burp Suite Professional Edition" use OpenSSL, Please let me know if "Burp Suite Professional Edition" is affected by CVE-2021-3711 and CVE-2021-3712. Thank you.

Michelle, PortSwigger Agent | Last updated: Sep 30, 2021 09:42AM UTC

Thanks for your message. Although Burp Suite Professional does not use OpenSSL, Burp's embedded browser uses Google's SSL library (built on top of OpenSSL). Any vulnerabilities here should be covered by Chrome's CVEs. Please let us know if you have any questions.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.