Product Affected

This issue affects all versions of Junos Space.
Medium

Problem

An Improper Handling of Parameters vulnerability in the web interface of Juniper Networks Junos Space permits the name of an arbitrarily supplied URL parameter to be copied into a response within the query string of a URL, allowing an attacker to craft a URL executed by the user to obtain unspecified information about the system or deliver unexpected results to the affected user.

Client-side HTTP parameter pollution (HPP) vulnerabilities arise when an application embeds user input in URLs in an unsafe manner. An attacker can use this vulnerability to construct a URL that, if visited by another application user, will modify URLs within the response by inserting additional query string parameters and sometimes overriding existing ones. This may result in links and forms having unexpected side effects. For example, it may be possible to modify an invitation form using HPP so that the invitation is delivered to an unexpected recipient.

This issue affects all versions of Junos Space before 24.1R4.

 

Juniper SIRT is not aware of any malicious exploitation of this vulnerability.

This issue was found during internal product security testing or research.

Solution

The following software releases have been updated to resolve this specific issue: Junos Space 24.1R4, and all subsequent releases.

 

This issue is being tracked as 1844574 which is visible on the Customer Support website.

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

There are no known workarounds for this issue.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net], "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2025-10-08: Initial Publication

Related Information