Multiple vulnerabilities have been resolved in the Junos Space Log Collector by updating third party software included with Junos Space or by fixing vulnerabilities found during external security research.
These issues affect Juniper Networks Junos Space Log Collector
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues were discovered during external security research. Security issues resolved include:
For the resolved CVEs the following software releases have been updated to resolve these specific issues: 20.3R1, and all subsequent releases.
For the unresolved CVEs Juniper Networks will not be resolving these issues.
Customers should contact their account managers for guidance on migration to other platforms.
These issues are being tracked as 1597018 .
There are no viable workarounds for these issues.
To reduce the risk of exploitation utilize common security BCPs to limit the exploitable surface by limiting access to the network and device to trusted systems, administrators, networks and hosts. Further protections can be gained by limiting shell access to only trusted system administrators and employing jump boxes on networks that have no Internet access.
2021-08-02: Initial Publication.