Session Fixation in Mozilla products - CVE-2020-15679

 

Session Fixation in Mozilla products - CVE-2020-15679

Published: November 5, 2020


Vulnerability identifier: #VU48164
CSH Severity: Medium
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-15679
CWE-ID: CWE-384
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to impersonate sessions of other application users.

The vulnerability exists within OAuth session handling functionality. A remote attacker can craft a custom login URL, convince a VPN user to login via that URL, and obtain authenticated access as that user.

This issue is limited to cases where attacker and victim are sharing the same source IP and could allow the ability to view session states and disconnect VPN sessions.


Affected software

Mozilla VPN Windows
Mozilla VPN iOS
Mozilla VPN Android

How to mitigate CVE-2020-15679

Install updates from vendor's website.

Mozilla VPN Windows - update to 1.2.2
Mozilla VPN iOS - update to 1.0.7
Mozilla VPN Android - update to 1.0.1

External References

Related Security Bulletins