Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-4104
HistorySep 11, 2023 - 12:00 a.m.

CVE-2023-4104

2023-09-1100:00:00
ubuntu.com
ubuntu.com
18
polkit authentication
d-bus methods
vpn setups
mozilla vpn
linux
vulnerability

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

0.0004 Low

EPSS

Percentile

5.1%

An invalid Polkit Authentication check and missing authentication
requirements for D-Bus methods allowed any local user to configure
arbitrary VPN setups. This bug only affects Mozilla VPN on Linux. Other
operating systems are unaffected.
This vulnerability affects Mozilla VPN
client for Linux < v2.16.1.

OSVersionArchitecturePackageVersionFilename
ubuntu22.04noarchmozillavpn< anyUNKNOWN

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

0.0004 Low

EPSS

Percentile

5.1%