UBUNTU-CVE-2023-4104

Source
https://ubuntu.com/security/CVE-2023-4104
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-4104.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2023-4104
Published
2023-09-11T09:15:00Z
Modified
2025-07-07T07:01:57.956060Z
Upstream
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
  • - medium
Summary
[none]
Details

An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups. This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected. This vulnerability affects Mozilla VPN client for Linux < v2.16.1.

References

Affected packages

Ubuntu:22.04:LTS / mozillavpn

Package

Name
mozillavpn
Purl
pkg:deb/ubuntu/mozillavpn@2.2.0-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.2.0-1