Multiple SAML authentication vulnerabilities in Juniper Networks Mist Cloud UI have been resolved in the release with date September 2 2020.
Juniper Networks Mist Cloud UI, when SAML authentication is enabled, may incorrectly handle SAML responses, allowing a remote attacker to bypass SAML authentication security controls.
If SAML authentication is not enabled, the product is not affected.
These vulnerabilities can be exploited alone or in combination. The CVSS score below represents the worst case chaining of these vulnerabilities.
This issue affects all Juniper Networks Mist Cloud UI versions prior to September 2 2020.
This issue was found during internal product security testing or research.
Important security issues resolved include:
Mist Cloud UI has been updated on September 2 2020 to resolve this specific issue.
Software releases or updates are available for download at https://www.juniper.net/support/downloads/ .
No workarounds are required since the issue has been resolved in the Mist cloud UI.
2020-10-14: Initial Publication.