PT-2022-8577 · Mozilla · Vpn
Published
2022-12-22
·
Updated
2022-12-29
·
CVE-2020-15679
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Mozilla VPN iOS versions 1.0.7 and earlier
Mozilla VPN Windows versions prior to 1.2.2
Mozilla VPN Android versions 1.1.0 and earlier
Description
An issue existed in the VPN login flow, where an attacker could craft a custom login URL and convince a VPN user to login via that URL, obtaining authenticated access as that user. This issue is limited to cases where the attacker and victim share the same source IP and could allow the ability to view session states and disconnect VPN sessions.
Recommendations
For Mozilla VPN iOS versions 1.0.7 and earlier, update to a version later than 1.0.7.
For Mozilla VPN Windows versions prior to 1.2.2, update to version 1.2.2 or later.
For Mozilla VPN Android versions 1.1.0 and earlier, update to a version later than 1.1.0.
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vpn