cbcvebase.
CVE-2023-4104
published 2023-09-11

CVE-2023-4104: An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups. *This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected.* This vulnerability affects Mozilla VPN 2.16.1 < (Linux).

Affected

3 ranges
VendorProductVersion rangeFixed in
mozillafirefox
mozillamozilla_vpn_2.16.1>= unspecified < (Linux)(Linux)
mozillavpn< 2.16.12.16.1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
osv5.5MEDIUM