Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-4104
HistorySep 11, 2023 - 9:15 a.m.

Authentication flaw

2023-09-1109:15:00
PRIOn knowledge base
www.prio-n.com
4
authentication
polkit
vulnerability
vpn
linux
mozilla

5.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups.
This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected. This vulnerability affects Mozilla VPN client for Linux < v2.16.1.

CPENameOperatorVersion
vpnlt2.16.1

5.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%