Multiple J-Web vulnerabilities have been resolved in Juniper Networks Junos OS.
These issues affect Juniper Networks Junos OS versions prior to 21.2R1.
The following minimal configuration is necessary:
[system services web-management http]
or
[system services web-management https]
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues were discovered during external security research.
Important security issues resolved include:
The following software releases have been updated to resolve these specific issues: Junos OS: 21.2R1 and all subsequent releases.
These issues are being tracked as 1460152 and 1560230 .
Software releases or updates are available for download at https://support.juniper.net/support/downloads/
There are no viable workarounds for these issues other than disabling J-Web.
To reduce the risk of exploitation of these issues, use access lists or firewall filters to limit access to only trusted administrative networks, hosts and users.
2021-07-14: Initial Publication.