PT-2021-18199 · Portswigger · Burp Suite

Issuefinder

·

Published

2021-03-29

·

Updated

2022-07-12

·

CVE-2021-29416

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: PortSwigger Burp Suite versions prior to 2021.2
Description: An issue was discovered where viewing a malicious request can be manipulated into issuing a request that does not respect its upstream proxy configuration. This could potentially leak NetNTLM hashes on Windows systems that fail to block outbound SMB.
Recommendations: For versions prior to 2021.2, update to version 2021.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the upstream proxy configuration to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-29416

Affected Products

Burp Suite