CVE-2023-4104: Mozilla VPN: CVE-2023-4104: Privileged vpndaemon on Linux wrongly and incompletely implements Polkit authentication
An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups. This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected. This vulnerability affects Mozilla VPN 2.16.1 < (Linux).
Other sources
An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups. This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected. This vulnerability affects Mozilla VPN client for Linux < v2.16.1.
— NVD
An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups.This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected.
— Mozilla
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-4104?
CVE-2023-4104 is a vulnerability in Mozilla VPN client for Linux that allows any local user to configure arbitrary VPN setups.
How does CVE-2023-4104 affect Mozilla VPN?
CVE-2023-4104 only affects Mozilla VPN client for Linux, other operating systems are unaffected.
What is the severity of CVE-2023-4104?
CVE-2023-4104 has a severity keyword of medium and a severity value of 5.5.
How do I fix CVE-2023-4104?
To fix CVE-2023-4104, you need to update Mozilla VPN client for Linux to version 2.16.1 or above.
Is there any additional information available on CVE-2023-4104?
For additional information on CVE-2023-4104, you can refer to the following references: [Bugzilla link](https://bugzilla.mozilla.org/show_bug.cgi?id=1831318), [GitHub PR #7110](https://github.com/mozilla-mobile/mozilla-vpn-client/pull/7110), [GitHub PR #7055](https://github.com/mozilla-mobile/mozilla-vpn-client/pull/7055).