CVE-2021-29416: Medium severity burp suite vulnerability
An issue was discovered in PortSwigger Burp Suite before 2021.2. During viewing of a malicious request, it can be manipulated into issuing a request that does not respect its upstream proxy configuration. This could leak NetNTLM hashes on Windows systems that fail to block outbound SMB.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-29416?
CVE-2021-29416 is considered a high-severity vulnerability due to the potential exposure of sensitive NetNTLM hashes.
How do I fix CVE-2021-29416?
To fix CVE-2021-29416, update your PortSwigger Burp Suite to version 2021.2 or later.
What systems are affected by CVE-2021-29416?
CVE-2021-29416 affects versions of PortSwigger Burp Suite prior to 2021.2 running on Windows systems with improperly configured outbound SMB blocking.
What kind of data could be leaked due to CVE-2021-29416?
CVE-2021-29416 could lead to the leakage of sensitive NetNTLM hashes, which can compromise user credentials.
Does CVE-2021-29416 affect both the Professional and Community editions?
Yes, CVE-2021-29416 affects both the Professional and Community editions of PortSwigger Burp Suite before version 2021.2.