CVE-2021-29978: Critical severity mozilla vpn vulnerability
Published Jul 14, 2021
·Updated
Multiple low security issues were discovered and fixed in a security audit of Mozilla VPN 2.x branch as part of a 3rd party security audit.
Affected Software
2 affected componentsFixes available
Mozilla Mozilla VPN<2.3
2.3
Mozilla Mozilla VPN>=2.0<2.3
Remediation
Event History
Jul 14, 2021
CVE Published
12:00 AM
Aug 5, 2021
CVE Published
via MITRE·07:45 PM
Data Sourced
via MITRE·07:45 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-29978?
The severity of CVE-2021-29978 is low.
2
What software is affected by CVE-2021-29978?
Mozilla VPN 2.x branch up to version 2.3 is affected by CVE-2021-29978.
3
How can I fix CVE-2021-29978?
Upgrade to version 2.3 of Mozilla VPN to fix CVE-2021-29978.
4
Where can I find more information about CVE-2021-29978?
You can find more information about CVE-2021-29978 in the following references: [GitHub issue 797](https://github.com/mozilla-mobile/mozilla-vpn-client/issues/797), [GitHub issue 798](https://github.com/mozilla-mobile/mozilla-vpn-client/issues/798), [GitHub issue 799](https://github.com/mozilla-mobile/mozilla-vpn-client/issues/799).