Burp Suite用户论坛

登录以发布

Java版本11.0.10-多个漏洞

肯上次更新:2021年12月1日09:23 AM UTC

嗨,昨天我安装了企业版2021.11的新副本。一夜之间,它被Nessus扫描了... --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------甲骨文Java SE 1.7.0_311 / 1.8.0_301 / 1.11.0_12 / 1.16.0_2多个漏洞(UNIX 2021年7月CPU)在远程主机上安装了以下JAVA的漏洞实例:路径: / opt / opt / opt / burpsuite_enterprise安装版本1.8.0_301 / 1.11.0_12 / 1.16.0_2 --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- The version information from the about screen... -------------------------------------------------------------------------------- Version: 2021.11-8333, Java version: 11.0.10 -------------------------------------------------------------------------------- The version for java confirmed.... -------------------------------------------------------------------------------- root@hostname:/opt/burpsuite_enterprise/jre/bin# ./java --version openjdk 11.0.10 2021-01-19 LTS OpenJDK Runtime Environment Corretto-11.0.10.9.1 (build 11.0.10+9-LTS) OpenJDK 64-Bit Server VM Corretto-11.0.10.9.1 (build 11.0.10+9-LTS, mixed mode) -------------------------------------------------------------------------------- Checked to see if there any anything other copies of java on the system, there are not. -------------------------------------------------------------------------------- root@hostname:/opt/burpsuite_enterprise/jre/bin# find / -name java /opt/burpsuite_enterprise/jre/bin/java /etc/apparmor.d/abstractions/ubuntu-browsers.d/java /usr/share/bash-completion/completions/java /usr/share/java (this is a directory!) -------------------------------------------------------------------------------- Is if safe me to try updating the bundled openjdk to 11.0.12? Or should I wait for a Burp update? Also, why wasn't the 2021.11-8333 version which was released on 11 November 2021 bundled with the latest version of openjdk; It's been available since July? v11.0.10 was released Jan 2021 - https://mail.openjdk.java.net/pipermail/jdk-updates-dev/2021-January/004689.html v11.0.11 was released April 2021 - https://mail.openjdk.java.net/pipermail/jdk-updates-dev/2021-April/005860.html v11.0.12 was released July 20th 2021 - https://mail.openjdk.java.net/pipermail/jdk-updates-dev/2021-July/006954.html Regards Ken

Alex,Pbeplay官网可以赌ortswigger代理|上次更新:2021年12月1日03:42 UTC

嗨,肯,谢谢您的帖子。我们目前正在进行更新,将Java版本提高到Burp Suite Enterprise的11.0.13-我目前没有确切的ETA,但我可以通过此线程更新您。我们不建议尝试手动更新捆绑版本。从历史上看,这对我们来说并不是一个简单的过程,即保持发行版,但是开发团队正在努力更快地进行更改。同样,我没有确切的ETA,但我会及时保持最新状态。谢谢

肯上次更新:2022年2月25日12:46 pm UTC

亚历克斯,我看到最近发布了一个新版本的BURP(//www.muteki-anime.com/burp/releases/enterpribeplay官网可以赌se-edition-2022-2)。我们的Burp Enterprise Server自动在夜间自动更新,我可以从“关于”页面上看到它正在运行Java 11.0.13。不幸的是,Nessus仍在报告Java 11.0.10。---------------------------------------------------------------------------------------------------------------------------------------------------- $ sudo find . -name java ./jre/bin/java ./jres/11.0.13.8.1/bin/java ./jres/11.0.10.9.1/bin/java $ ./jre/bin/java -version openjdk version "11.0.10" 2021-01-19 LTS OpenJDK Runtime Environment Corretto-11.0.10.9.1 (build 11.0.10+9-LTS) OpenJDK 64-Bit Server VM Corretto-11.0.10.9.1 (build 11.0.10+9-LTS, mixed mode) $ ./jres/11.0.13.8.1/bin/java -version -bash: ./jres/11.0.13.8.1/bin/java: Permission denied $ sudo ./jres/11.0.13.8.1/bin/java -version openjdk version "11.0.13" 2021-10-19 LTS OpenJDK Runtime Environment Corretto-11.0.13.8.1 (build 11.0.13+8-LTS) OpenJDK 64-Bit Server VM Corretto-11.0.13.8.1 (build 11.0.13+8-LTS, mixed mode) $ ./jres/11.0.10.9.1/bin/java -version -bash: ./jres/11.0.10.9.1/bin/java: Permission denied $ sudo ./jres/11.0.10.9.1/bin/java -version openjdk version "11.0.10" 2021-01-19 LTS OpenJDK Runtime Environment Corretto-11.0.10.9.1 (build 11.0.10+9-LTS) OpenJDK 64-Bit Server VM Corretto-11.0.10.9.1 (build 11.0.10+9-LTS, mixed mode) ------------------------------------------------------------------------------------------ Can you explain to me how do I go about removing the 11.0.10 components because Burp's automatic updating doesn't do it. Thanks

Alex,Pbeplay官网可以赌ortswigger代理|上次更新:2022年3月2日09:17 AM UTC

嗨,肯,通过遵循Burp Suite Enterprise的升级路径(与新安装相对),将保留基本JRE版本。Web应beplay体育能用吗用程序将始终将安装的任何新JRE版本作为更新的一部分,但是原件将保持小型主管卷以停止/启动某些服务。值得注意的是,我们使用自定义JDK,因此安全扫描仪可能标记的任何依赖项都不一定适用于Burp Suite Enterprise。如果您希望我们检查任何特定标记的漏洞,我们很乐意这样做。谢谢

布莱恩|上次更新:2022年4月6日04:49 UTC

我们可以在何时为Open vuln修补OpenJDK版本11.0.13.8.1时获得更新吗?CVE-2022-21341 CVE-2022-21360 CVE-20222-21365 CVE-2022-21282 CVE-2022-21296 CVE-202222222222222222291 CVE-20222222-21305

Alex,Pbeplay官网可以赌ortswigger代理|最后更新:2022年4月7日09:35 AM UTC

嗨,布莱恩,我们的Java 11.0.14升级将在下一个企业版本中进行。此外,我已经在开发团队中确认Burp Suite Enterprise并未暴露于列出的问题。谢谢

你需要登录发布答复。或者在这里注册, 免费。