First published: Thu Aug 03 2023(Updated: )
An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups. *This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected.* This vulnerability affects Mozilla VPN client for Linux < v2.16.1.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Mozilla VPN client for Linux v | <2.16.1 | 2.16.1 |
Mozilla Vpn | <2.16.1 | |
<2.16.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4104 is a vulnerability in Mozilla VPN client for Linux that allows any local user to configure arbitrary VPN setups.
CVE-2023-4104 only affects Mozilla VPN client for Linux, other operating systems are unaffected.
CVE-2023-4104 has a severity keyword of medium and a severity value of 5.5.
To fix CVE-2023-4104, you need to update Mozilla VPN client for Linux to version 2.16.1 or above.
For additional information on CVE-2023-4104, you can refer to the following references: [Bugzilla link](https://bugzilla.mozilla.org/show_bug.cgi?id=1831318), [GitHub PR #7110](https://github.com/mozilla-mobile/mozilla-vpn-client/pull/7110), [GitHub PR #7055](https://github.com/mozilla-mobile/mozilla-vpn-client/pull/7055).