CVSS: v3.1: 9.0 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)CVSS: v4.0: 6.4 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/R:U/RE:M)
Multiple Cross-site Scripting (XSS) vulnerabilities have been resolved in the Juniper Networks Junos Space 24.1R4 release.These issues affect Juniper Networks Junos Space versions prior to 24.1R4.
Important security issues resolved include:
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
These issues were found during internal product security testing or research.
The following software releases have been updated to resolve these issues: Junos Space 24.1R4 and all subsequent releases.
This issue is being tracked as 1878088, 1871861, 1872361, 1872047, 1873493, 1872656, 1872279, 1872378, 1872380, 1873140, 1873134, 1872653, 1872495, 1872374, 1870550, 1873233, 1873107, 1872470, 1872032, 1872201, 1870551, 1809262, 1872060 and 1877685 which are visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
There are no known workarounds for these issues.
2025-10-08: Initial Publication2025-10-14: Added missing attribution to NATO Cyber Security Center for responsibly reporting CVE-2025-59978
Juniper SIRT would like to acknowledge and thank Arnoldas Radisauskas and Jorge Escabias from NATO Cyber Security Center for responsibly reporting CVE-2025-59978.