PT-2023-4835 · Mozilla · Vpn
Matthias Gerstner
·
Published
2023-08-30
·
Updated
2023-09-13
·
CVE-2023-4104
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mozilla VPN client for Linux versions prior to 2.16.1
Description
The issue is related to an invalid Polkit Authentication check and missing authentication requirements for D-Bus methods, allowing any local user to configure arbitrary VPN setups. This bug only affects Mozilla VPN on Linux, with other operating systems being unaffected.
Recommendations
For Mozilla VPN client for Linux versions prior to 2.16.1, update to version 2.16.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the D-Bus methods until a patch is available.
Exploit
Fix
Missing Authorization
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vpn