CVE-2020-15679: High severity mozilla vpn vulnerability
An OAuth session fixation vulnerability existed in the VPN login flow, where an attacker could craft a custom login URL, convince a VPN user to login via that URL, and obtain authenticated access as that user. This issue is limited to cases where attacker and victim are sharing the same source IP and could allow the ability to view session states and disconnect VPN sessions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-15679?
CVE-2020-15679 is an OAuth session fixation vulnerability in the VPN login flow where an attacker can craft a custom login URL and obtain authenticated access as a VPN user.
What is the severity of CVE-2020-15679?
The severity of CVE-2020-15679 is medium, with a severity value of 4.
Which software versions are affected by CVE-2020-15679?
CVE-2020-15679 affects Mozilla VPN Android (1360) version up to, but exclusive, 1.1.0, Mozilla VPN iOS (929) version up to, but exclusive, 1.0.7, and Mozilla VPN Windows version up to, but exclusive, 1.2.2.
How can an attacker exploit CVE-2020-15679?
An attacker can exploit CVE-2020-15679 by crafting a custom login URL, convincing a VPN user to login via that URL, and obtaining authenticated access as that user.
Where can I find more information about CVE-2020-15679?
You can find more information about CVE-2020-15679 at the following references: [link1], [link2], [link3].