First published: Tue Nov 30 2021(Updated: )
PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privilege escalation. This issue can be exploited by an adversary who has already compromised a valid Windows account on the server via separate means. In this scenario, the compromised account may have inherited read access to sensitive configuration, database, and log files.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Burp Suite | <=2021.11 | |
Microsoft Windows Operating System | ||
Burp Suite | <=2021.11 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-44230.
The severity of CVE-2021-44230 is medium with a severity value of 6.5.
The affected software is PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows.
This vulnerability can be exploited by an adversary who has already compromised a valid Windows account on the server via separate means.
To fix CVE-2021-44230, update to PortSwigger Burp Suite Enterprise Edition 2021.11 or later.