ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

← Back to results

CVE-2020-15679

An OAuth session fixation vulnerability existed in the VPN login flow, where an attacker could craft a custom login URL, convince a VPN user to login via that URL, and obtain authenticated access as that user. This issue is limited to cases where attacker and victim are sharing the same source IP and could allow the ability to view session states and disconnect VPN sessions. This vulnerability affects Mozilla VPN iOS 1.0.7 < (929), Mozilla VPN Windows < 1.2.2, and Mozilla VPN Android 1.1.0 < (1360).
An official patch is available. Apply the patch as soon as possible.
7.6
CVSS
5.3
ShadowTrackr
NO
CISA KEV
-
NCSC.nl
CVSS v4.0 Metrics
Exploitability
Attack VectorNetwork
ComplexityLow
RequirementsPresent
PrivilegesNone
User InteractionActive
Threat
Exploit MaturityPoC
Vulnerable System
ConfidentialityLow
IntegrityLow
AvailabilityHigh
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Patch StatusOfficial Patch

Change Log
DateSourceChangesScore
2026-07-21PoCE: U→P2.2 → 5.3
2026-07-21nvdpatch: Unavailable→Official Patch2.2 → 2.2
2026-07-21cve.orginitial, patch: Unavailable2.2

Affected Software
VendorProductVersion
MozillaMozilla VPN Android 1.1.0< (1360)
MozillaMozilla VPN iOS 1.0.7< (929)
MozillaMozilla VPN Windows< 1.2.2
mozillavpn< 1.0.7_\(929\)
mozillavpn< 1.2.2
mozillavpn≥ 1.0.7, < 1.0.7_\(929\)
mozillavpn≥ 1.1.0, < 1.1.0_\(1360\)
Published: 2022-12-22