Multiple vulnerabilities have been resolved in Juniper Networks Contrail Service Orchestration (CSO), by updating third party software included with Contrail Service Orchestration (CSO) or by fixing vulnerabilities found during external security research.
These issue affects:
Juniper Networks Contrail Service Orchestration (CSO)
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues were discovered during external security research.
Important security issues resolved include:
The following software releases have been updated to resolve these specific issues: Juniper Networks Contrail Service Orchestration (CSO) 5.1.2, 6.1.0, and all subsequent releases.
Please note: a fix patch for 5 releases is only available for 5.1.2 On-Premises releases.
For 6.0 and 6.1 upgrade installations, the patch is included. For new installations, run the setup_bms.sh file to download the latest version. setup_bms.sh is part of the deployment.
The upgrade steps are:
Point /etc/apt/sources.list to internet debian repo:
cp /etc/apt/sources.list /etc/apt/sources.list_dnsmasq_base
cp /etc/apt/orig-sources.list /etc/apt/sources.list
apt-get update
apt-get --only-upgrade install dnsmasq-base
cp /etc/apt/sources.list_dnsmasq_base /etc/apt/sources.list
These issues are being tracked as CXU-55020.
Software releases or updates are available for download at https://support.juniper.net/support/downloads/
2021-10-13: Initial Publication.