CVE-2021-29416
29.03.2021, 18:15
An issue was discovered in PortSwigger Burp Suite before 2021.2. During viewing of a malicious request, it can be manipulated into issuing a request that does not respect its upstream proxy configuration. This could leak NetNTLM hashes on Windows systems that fail to block outbound SMB.Enginsight
Vendor | Product | Version |
---|---|---|
portswigger | burp_suite | 𝑥 < 2021.2 |
portswigger | burp_suite | 𝑥 < 2021.2 |
𝑥
= Vulnerable software versions