The following vulnerabilities have been resolved in the Contrail Service Orchestration (CSO) 4.0.0 release:
The following vulnerabilities have been resolved in the Contrail Service Orchestration (CSO) 3.3.0 release:
Contrail Service Orchestration is affected by the following issue:
CVE-2018-0039, CVE-2018-0040, CVE-2018-0042
These issues are fixed in Contrail Service Orchestration 4.0.0 and subsequent releases.
CVE-2018-0038, CVE-2018-0041
These issues are fixed in Contrail Service Orchestration 3.3.0 and subsequent releases.
CVE-2018-1000115
A resolution is pending in Contrail Service Orchestration. Use the suggested workaround to block access to memcached.
These issues are being tracked as Contrail defects CXU-17923, CXU-5666, CXU-5678, CXU-5933, CXU-5819 and CXU-23803.
CSO software releases, patches and updates are available at https://www.juniper.net/support/downloads/?p=cso .
Limit access to the Contrail Service Orchestration environment to only trusted networks and hosts. The following workarounds apply to specific issues:
CVE-2018-0039
2018-07-11: Initial Publication.