Multiple vulnerabilities in third party software used in Juniper Networks Contrail Networking have been resolved in release 2011.
Additionally, CVE-2019-17571 affect Contrail Networking versions prior to 2011.L1, CVE-2020-27223 affect Contrail Networking versions prior to 2011.L2, and CVE-2020-14343 and CVE-2021-21309 affect Contrail Networking versions prior to 2011.L3.
These issues affect Juniper Networks Contrail Networking versions prior to 2011.
This issue was discovered during external security research.
Important security issues resolved include:
The following software releases have been updated to resolve these specific issues: Contrail Networking 2011, and all subsequent releases.
These issues are being tracked as CEM-18632, CEM-21800, CEM-23697 and CEM-23971.
Software releases or updates are available for download at https://support.juniper.net/support/downloads/
There are no known workarounds for this issue.
2022-01-12: Initial Publication.2022-12-21: Added CVE-2021-21309 to list of resolved vulnerabilities.