Multiple vulnerabilities in third party software used in Juniper Networks Contrail Networking have been resolved in Release 1910.
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues include:
These issues have been resolved in Contrail Networking Release 1910.
This issue is being tracked as Contrail JIRA issues CEM-8320, CEM-8146, CEM-8567, CEM-6975, CEM-8477, CEM-8582, CEM-8583 and CEM-9136.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Software Releases, patches and updates are available at https://www.juniper.net/support/downloads/ .
There are no viable workarounds for all these issues.
2019-10-09: Initial publication 2020-11-20: Updated terminology