Patch & vulnerability status
PortSwigger Web Security
Burp Suite Community Stable 2025.8.4
Latest tracked version 2025.8.4. Release status, tracked CVEs, and automated cross-platform patching for Burp Suite Community Stable.
Category: Security
| Platform | Latest version | CVEs tracked | Last checked |
|---|---|---|---|
| Windows | 2025.8.4 | 7 | 2025-09-16 |
Known vulnerabilities (CVEs) in Burp Suite Community Stable
Lavawall tracks 7 published CVEs affecting Burp Suite Community Stable, and deploys the versions that fix them automatically across your fleet.
| CVE | Published | Severity | Details | Vector |
|---|---|---|---|---|
| CVE-2022-35406 | 2022-07-08 16:15:08 | MEDIUM (4) | A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect. | NETWORK |
| CVE-2021-44230 | 2021-11-30 19:15:10 | MEDIUM (7) | PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privilege escalation. This issue can be exploited by an adversary who has already compromised a valid Windows account on the server via separate means. In this scenario, the compromised account may have inherited read access to sensitive configuration, database, and log files. | NETWORK |
| CVE-2021-29416 | 2021-03-29 18:15:13 | MEDIUM (7) | An issue was discovered in PortSwigger Burp Suite before 2021.2. During viewing of a malicious request, it can be manipulated into issuing a request that does not respect its upstream proxy configuration. This could leak NetNTLM hashes on Windows systems that fail to block outbound SMB. | NETWORK |
| CVE-2018-1153 | 2018-06-18 14:29:00 | MEDIUM (6) | Burp Suite Community Edition 1.7.32 and 1.7.33 fail to validate the server certificate in a couple of HTTPS requests which allows a man in the middle to modify or view traffic. | NETWORK |
| CVE-2018-10377 | 2018-06-17 16:29:00 | MEDIUM (4) | PortSwigger Burp Suite before 1.7.34 has Improper Certificate Validation of the Collaborator server certificate, which might allow man-in-the-middle attackers to obtain interaction data. | NETWORK |
| CVE-2017-18285 | 2018-06-04 06:29:00 | LOW (4) | The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might allow local users to obtain read and write access to arbitrary files by leveraging access to a certain account for a burp-server.conf change. | LOCAL |
| CVE-2017-18284 | 2018-06-04 06:29:00 | LOW (4) | The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL. | LOCAL |
Why keeping Burp Suite Community Stable patched matters
Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every Burp Suite Community Stable release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.
How Lavawall® patches Burp Suite Community Stable
Lavawall® watches Burp Suite Community Stable releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on Burp Suite Community Stable, one policy to bring them current, and timestamped evidence for audits.
Frequently asked questions
Lavawall tracks Burp Suite Community Stable at version 2025.8.4 (last checked 2025-09-16). New releases are monitored continuously and can be deployed automatically across your fleet.
Lavawall tracks 7 CVEs for Burp Suite Community Stable and remediates them automatically as part of patching.
Deploy the Lavawall® agent and Burp Suite Community Stable updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.
Lavawall® monitors releases and CVEs for Burp Suite Community Stable through public information and proprietary statistical analysis, and can patch it automatically across your fleet.