PT-2021-18199 · Portswigger · Burp Suite
Issuefinder
·
Published
2021-03-29
·
Updated
2022-07-12
·
CVE-2021-29416
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
PortSwigger Burp Suite versions prior to 2021.2
Description:
An issue was discovered where viewing a malicious request can be manipulated into issuing a request that does not respect its upstream proxy configuration. This could potentially leak NetNTLM hashes on Windows systems that fail to block outbound SMB.
Recommendations:
For versions prior to 2021.2, update to version 2021.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the upstream proxy configuration to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Burp Suite