Vulnerability CVE-2021-29978


Published: 2021-08-05

Description:
Multiple low security issues were discovered and fixed in a security audit of Mozilla VPN 2.x branch as part of a 3rd party security audit. This vulnerability affects Mozilla VPN < 2.3.

Type:

NVD-CWE-noinfo

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Mozilla -> Mozilla vpn 

 References:
https://github.com/mozilla-mobile/mozilla-vpn-client/issues/803
https://github.com/mozilla-mobile/mozilla-vpn-client/pull/816
https://github.com/mozilla-mobile/mozilla-vpn-client/issues/805
https://github.com/mozilla-mobile/mozilla-vpn-client/issues/804
https://github.com/mozilla-mobile/mozilla-vpn-client/issues/806
https://github.com/mozilla-mobile/mozilla-vpn-client/issues/809
https://github.com/mozilla-mobile/mozilla-vpn-client/issues/808
https://github.com/mozilla-mobile/mozilla-vpn-client/issues/797
https://github.com/mozilla-mobile/mozilla-vpn-client/issues/799
https://github.com/mozilla-mobile/mozilla-vpn-client/issues/810
https://github.com/mozilla-mobile/mozilla-vpn-client/issues/798
https://github.com/mozilla-mobile/mozilla-vpn-client/issues/801
https://github.com/mozilla-mobile/mozilla-vpn-client/issues/812
https://github.com/mozilla-mobile/mozilla-vpn-client/issues/800
https://www.mozilla.org/security/advisories/mfsa2021-31/

Copyright 2024, cxsecurity.com

 

Back to Top