5.5 Medium
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
0.0004 Low
EPSS
Percentile
5.1%
An invalid Polkit Authentication check and missing authentication
requirements for D-Bus methods allowed any local user to configure
arbitrary VPN setups. This bug only affects Mozilla VPN on Linux. Other
operating systems are unaffected. This vulnerability affects Mozilla VPN
client for Linux < v2.16.1.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 22.04 | noarch | mozillavpn | < any | UNKNOWN |