CVE-2021-44230: Medium severity burp suite vulnerability
PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privilege escalation. This issue can be exploited by an adversary who has already compromised a valid Windows account on the server via separate means. In this scenario, the compromised account may have inherited read access to sensitive configuration, database, and log files.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-44230.
What is the severity of CVE-2021-44230?
The severity of CVE-2021-44230 is medium with a severity value of 6.5.
What is the affected software?
The affected software is PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows.
How can this vulnerability be exploited?
This vulnerability can be exploited by an adversary who has already compromised a valid Windows account on the server via separate means.
How can I fix CVE-2021-44230?
To fix CVE-2021-44230, update to PortSwigger Burp Suite Enterprise Edition 2021.11 or later.