PT-2023-4835 · Mozilla · Vpn
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mozilla VPN client for Linux versions prior to 2.16.1
Description
The issue is related to an invalid Polkit Authentication check and missing authentication requirements for D-Bus methods, allowing any local user to configure arbitrary VPN setups. This bug only affects Mozilla VPN on Linux, with other operating systems being unaffected.
Recommendations
For Mozilla VPN client for Linux versions prior to 2.16.1, update to version 2.16.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the D-Bus methods until a patch is available.
Exploit
Correção
Missing Authorization
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Vpn