Burp Suite User Forum

Create new post

OMIGOD Vulnerability

Perez, | Last updated: Oct 04, 2021 11:49PM UTC

There are 4 vulnerabilities impacting Linux servers. These go by OMIGOD. CVE-2021-38647 – Unauthenticated RCE as root (Severity: 9.8) CVE-2021-38648 – Privilege Escalation vulnerability (Severity: 7.8) CVE-2021-38645 – Privilege Escalation vulnerability (Severity: 7.8) CVE-2021-38649 – Privilege Escalation vulnerability (Severity: 7.0) All OMI versions below v1.6.8-1 are vulnerable. We noted that in our Azure PaaS instance of BurpSuite there are several Linux server. Does this impact BurpSuite? Is that something that Azure would Handle?

Alex, PortSwigger Agent | Last updated: Oct 05, 2021 01:14PM UTC

Hi Fernando, Thanks for your post. I believe Microsoft has published fixes and guidance for those vulnerabilities mentioned: https://msrc-blog.microsoft.com/2021/09/16/additional-guidance-regarding-omi-vulnerabilities-within-azure-vm-management-extensions/ Thanks

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.