Product Affected

These issues affect all versions of Junos OS prior to 21.2R1.
High
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Problem

Multiple J-Web vulnerabilities have been resolved in Juniper Networks Junos OS.

These issues affect Juniper Networks Junos OS versions prior to 21.2R1.

The following minimal configuration is necessary:

[system services web-management http]

or

[system services web-management https]


Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.

These issues were discovered during external security research.

Important security issues resolved include:

CVE CVSS Summary
CVE-2016-7103 6.1 ( CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N ) Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
CVE-2019-11358 6.1 ( CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N ) jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
CVE-2020-7656 4.3  AV:N/AC:M/Au:N/C:N/I:P/A:N jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove " <script> ", which results in the enclosed script logic to be executed.

Solution

The following software releases have been updated to resolve these specific issues: Junos OS: 21.2R1 and all subsequent releases.

These issues are being tracked as  1460152  and  1560230 .
 

Software releases or updates are available for download at https://support.juniper.net/support/downloads/
 

Workaround

There are no viable workarounds for these issues other than disabling J-Web.

To reduce the risk of exploitation of these issues, use access lists or firewall filters to limit access to only trusted administrative networks, hosts and users.
 

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2021-07-14: Initial Publication.

Related Information