QID 630670
Date Published: 2021-04-07
QID 630670: Mozilla VPN For Android and iOS OAuth Session Fixation Vulnerability (MFSA2020-48)
An OAuth session fixation vulnerability existed in the VPN login flow, where an attacker could craft a custom login URL, convince a VPN user to login via that URL, and obtain authenticated access as that user.
Affected Versions
Mozilla VPN Android 1.1.0 (1360)
Mozilla VPN iOS 1.0.7 (929)
On successful exploitation an attacker can run arbitrary code.
Solution
Upgrade to the latest packages which contain a patch. Refer to mfsa2020-48 to address this issue and obtain more information.
Vendor References
- MFSA2020-48 -
www.mozilla.org/en-US/security/advisories/mfsa2020-48/
CVEs related to QID 630670
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| mfsa2020-48 | Android |
|
|
| mfsa2020-48 | iOS |
|