SB2020110542 - Session fixation in Mozilla VPN
Published: November 5, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Session Fixation (CVE-ID: CVE-2020-15679)
The vulnerability allows a remote attacker to impersonate sessions of other application users.
The vulnerability exists within OAuth session handling functionality. A remote attacker can craft a custom login URL, convince a VPN user to login via that URL, and obtain authenticated access as that user.
This issue is limited to cases where attacker and victim are sharing the same source IP and could allow the ability to view session states and disconnect VPN sessions.
Remediation
Install update from vendor's website.