PT-2018-9859 · Portswigger · Burp Suite

Bruno Morisson

·

Published

2018-06-17

·

Updated

2018-08-14

·

CVE-2018-10377

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: PortSwigger Burp Suite versions prior to 1.7.34
Description: The issue concerns improper certificate validation of the Collaborator server certificate. This could potentially allow man-in-the-middle attackers to obtain interaction data.
Recommendations: For versions prior to 1.7.34, update to version 1.7.34 or later to resolve the issue.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10377

Affected Products

Burp Suite