CVE-2021-29978
Summary
| CVE | CVE-2021-29978 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-05 20:15:00 UTC |
| Updated | 2021-08-13 13:12:00 UTC |
| Description | Multiple low security issues were discovered and fixed in a security audit of Mozilla VPN 2.x branch as part of a 3rd party security audit. This vulnerability affects Mozilla VPN < 2.3. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Mozilla Vpn | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| FVP-02-003 General: Balrog incorrectly verifies certificate chain · Issue #798 · mozilla-mobile/mozilla-vpn-client · GitHub | MISC | github.com | |
| FVP-02-005 WP1-3: Authenticationlistener allows disturbance of login · Issue #800 · mozilla-mobile/mozilla-vpn-client · GitHub | MISC | github.com | |
| FVP-02-002 WP1: Balrog does not verify certificate chain on macOS · Issue #797 · mozilla-mobile/mozilla-vpn-client · GitHub | MISC | github.com | |
| FVP-02-012 WP5: Unencrypted shared preferences · Issue #808 · mozilla-mobile/mozilla-vpn-client · GitHub | MISC | github.com | |
| FVP-02-010 WP5: Android app supports insecure v1 signature · Issue #805 · mozilla-mobile/mozilla-vpn-client · GitHub | MISC | github.com | |
| FVP-02-008 WP5: Android app allows backups of application data · Issue #803 · mozilla-mobile/mozilla-vpn-client · GitHub | MISC | github.com | |
| FVP-02-014 General: Cross-site WebSocket hijacking · Issue #810 · mozilla-mobile/mozilla-vpn-client · GitHub | MISC | github.com | |
| FVP-02-009 WP5: Secure flag missing on views for Android app · Issue #804 · mozilla-mobile/mozilla-vpn-client · GitHub | MISC | github.com | |
| Multiple Low Security Issues in Mozilla VPN — Mozilla | MISC | www.mozilla.org | |
| FVP-02-006 WP3: Race condition in Ping Sender could expose gateway IP · Issue #801 · mozilla-mobile/mozilla-vpn-client · GitHub | MISC | github.com | |
| FVP-02-013 WP5: Android app exposes sensitive data to system logs · Issue #809 · mozilla-mobile/mozilla-vpn-client · GitHub | MISC | github.com | |
| FVP-02-005 WP1-3: Authenticationlistener allows disturbance of login by bakulf · Pull Request #816 · mozilla-mobile/mozilla-vpn-client · GitHub | MISC | github.com | |
| FVP-02-016 OAuth: Auth code could be leaked by injecting port · Issue #812 · mozilla-mobile/mozilla-vpn-client · GitHub | MISC | github.com | |
| FVP-02-011 API: Information disclosure via device endpoint · Issue #806 · mozilla-mobile/mozilla-vpn-client · GitHub | MISC | github.com | |
| FVP-02-004 WP4: ATS policy unnecessarily weakened · Issue #799 · mozilla-mobile/mozilla-vpn-client · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.