First published: Wed Nov 04 2020(Updated: )
OAuth session fixation vulnerability in Mozilla VPN
Affected Software | Affected Version | How to fix |
---|---|---|
<1.1.0 | 1.1.0 | |
<1.0.7 | 1.0.7 | |
<1.2.2 | 1.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
MFSA2020-48 is classified as a high severity vulnerability affecting OAuth session management.
MFSA2020-48 affects Mozilla VPN for Android versions below 1.1.0, iOS versions below 1.0.7, and Windows versions below 1.2.2.
To fix MFSA2020-48, update your Mozilla VPN to Android version 1.1.0, iOS version 1.0.7, or Windows version 1.2.2 or later.
MFSA2020-48 is an OAuth session fixation vulnerability that can lead to unauthorized access.
Yes, MFSA2020-48 can potentially compromise user data by allowing attackers to hijack user sessions.