Lucene search

K
cvelistMozillaCVELIST:CVE-2023-4104
HistorySep 11, 2023 - 8:02 a.m.

CVE-2023-4104

2023-09-1108:02:53
mozilla
www.cve.org
polkit
authentication
mozilla vpn
linux
vulnerability

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups.
This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected. This vulnerability affects Mozilla VPN client for Linux < v2.16.1.

CNA Affected

[
  {
    "product": "Mozilla VPN client for Linux",
    "vendor": "Mozilla",
    "versions": [
      {
        "lessThan": "v2.16.1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVELIST:CVE-2023-4104