CVE-2020-15679

Source
https://cve.org/CVERecord?id=CVE-2020-15679
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15679.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-15679
Published
2022-12-22T20:15:10.730Z
Modified
2026-04-11T12:40:04.781524Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H CVSS Calculator
Summary
[none]
Details

An OAuth session fixation vulnerability existed in the VPN login flow, where an attacker could craft a custom login URL, convince a VPN user to login via that URL, and obtain authenticated access as that user. This issue is limited to cases where attacker and victim are sharing the same source IP and could allow the ability to view session states and disconnect VPN sessions. This vulnerability affects Mozilla VPN iOS 1.0.7 < (929), Mozilla VPN Windows < 1.2.2, and Mozilla VPN Android 1.1.0 < (1360).

References

Affected packages

Git / github.com/mozilla-mobile/guardian-vpn-android

Affected ranges

Type
GIT
Repo
https://github.com/mozilla-mobile/guardian-vpn-android
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/mozilla-mobile/guardian-vpn-ios
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/mozilla-services/guardian-vpn-windows-deprecated
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/mozilla-mobile/guardian-vpn-android
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/mozilla-mobile/guardian-vpn-ios
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/mozilla-services/guardian-vpn-windows-deprecated
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*
1.0.1
1.0.2
v0.*
v0.13
v0.15
v1.*
v1.0.0
v1.0.1
v1.0.1-rc1
v1.0.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15679.json"
vanir_signatures
[
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "230911635598706793484908627318994051684",
                "41941928431531289393092008962610217027"
            ]
        },
        "source": "https://github.com/mozilla-mobile/guardian-vpn-ios/commit/4309f5c9bd2c15cdfd39ac173665fad3f2598b54",
        "id": "CVE-2020-15679-cb1e4e25",
        "signature_type": "Line",
        "target": {
            "file": "FirefoxPrivateNetworkVPN/Project Files/Bridging-Header.h"
        }
    }
]
vanir_signatures_modified
"2026-04-11T12:40:04Z"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "1.0.7_\\(929\\)"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "1.2.2"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "1.0.7"
            },
            {
                "fixed": "1.0.7_\\(929\\)"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "1.1.0"
            },
            {
                "fixed": "1.1.0_\\(1360\\)"
            }
        ]
    }
]