Multiple vulnerabilities have been resolved in the Junos Space 20.3R1 release by updating third party software included with Junos Space or by fixing vulnerabilities found during external security research.
These issues affect Juniper Networks Junos Space versions prior to 20.3R1.
Important security issues resolved include:
The following software releases have been updated to resolve these specific issues: Junos Space 20.3R1, and all subsequent releases.
These issues are being tracked as 1524812 , 1516351 and 1519331 .
Software releases or updates are available for download at https://www.juniper.net/support/downloads/ .
There are no known workarounds for these issues.
To reduce the risk of exploitation of these issues, use access lists or firewall filters to limit access to Junos Space to only trusted administrative networks, hosts and users.
2021-01-13: Initial Publication.
Juniper SIRT would like to acknowledge and thank Bruno Colella Garofalo for responsibly reporting CVE-2021-0220.