2024-08-01 14:03:18 +00:00

76 lines
2.6 KiB
JSON

{
"id": "CVE-2024-34446",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-05-03T15:15:08.210",
"lastModified": "2024-08-01T13:52:21.980",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Mullvad VPN through 2024.1 on Android does not set a DNS server in the blocking state (after a hard failure to create a tunnel), and thus DNS traffic can leave the device. Data showing that the affected device was the origin of sensitive DNS requests may be observed and logged by operators of unintended DNS servers."
},
{
"lang": "es",
"value": "Mullvad VPN hasta 2024.1 en Android no configura un servidor DNS en estado de bloqueo (despu\u00e9s de un error grave al crear un t\u00fanel) y, por lo tanto, el tr\u00e1fico DNS puede salir del dispositivo. Los operadores de servidores DNS no deseados pueden observar y registrar datos que muestren que el dispositivo afectado fue el origen de solicitudes DNS confidenciales."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-923"
}
]
}
],
"references": [
{
"url": "https://github.com/mullvad/mullvadvpn-app/blob/main/CHANGELOG.md",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/mullvad/mullvadvpn-app/commit/0c39306a40f426853d617e20d596942e41091f13",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/mullvad/mullvadvpn-app/tags",
"source": "cve@mitre.org"
},
{
"url": "https://mullvad.net/en/blog/dns-traffic-can-leak-outside-the-vpn-tunnel-on-android",
"source": "cve@mitre.org"
},
{
"url": "https://news.ycombinator.com/item?id=40247604",
"source": "cve@mitre.org"
}
]
}