CVE-2018-1153

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
18/06/2018
Last modified:
14/08/2018

Description

Burp Suite Community Edition 1.7.32 and 1.7.33 fail to validate the server certificate in a couple of HTTPS requests which allows a man in the middle to modify or view traffic.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:portswigger:burp_suite:1.7.32:*:*:*:community:*:*:*
cpe:2.3:a:portswigger:burp_suite:1.7.33:*:*:*:community:*:*:*