Skip to content

False Positive: BurpSuite Incorrectly Reports Dependency Confusion Vulnerability #7

Description

@k0ns0l

When viewing a package-lock.json file in the browser with JS-Miner active, a false positive HIGH Vulnerability alert for Dependency Confusion is consistently triggered.

The root cause might stems from an extraneous "{" character being included in the npm package search query. Thus this character is erroneously interpreted as part of the package name, leading to the false positives.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions