← Back

Portswigger

portswigger

5 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Burp Suite
burp_suite

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Portswigger
1Burp Suite
Nov 21, 2024
Jul 8, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect.
1Portswigger
1Burp Suite
Nov 21, 2024
Nov 30, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privilege escalation. This issue can be exploited by an adversary who has al...Show more
PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privilege escalation. This issue can be exploited by an adversary who has already compromised a valid Windows account on the server via separate means. In this scenario, the compromised account may have inherited read access to sensitive configuration, database, and log files.Show less
1Portswigger
1Burp Suite
Nov 21, 2024
Mar 29, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in PortSwigger Burp Suite before 2021.2. During viewing of a malicious request, it can be manipulated into issuing a request that does not respect its upstream proxy configuration. This could leak...Show more
An issue was discovered in PortSwigger Burp Suite before 2021.2. During viewing of a malicious request, it can be manipulated into issuing a request that does not respect its upstream proxy configuration. This could leak NetNTLM hashes on Windows systems that fail to block outbound SMB.Show less
1Portswigger
1Burp Suite
Nov 21, 2024
Jun 18, 2018
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Burp Suite Community Edition 1.7.32 and 1.7.33 fail to validate the server certificate in a couple of HTTPS requests which allows a man in the middle to modify or view traffic.
1Portswigger
1Burp Suite
Nov 21, 2024
Jun 17, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
PortSwigger Burp Suite before 1.7.34 has Improper Certificate Validation of the Collaborator server certificate, which might allow man-in-the-middle attackers to obtain interaction data.