Multiple vulnerabilities in third party software used in Juniper Networks Contrail Networking have been resolved in release 21.4.0 by upgrading the Open Container Initiative (OCI)-compliant Red Hat Universal Base Image (UBI) container image from Red Hat Enterprise Linux 7 to Red Hat Enterprise Linux 8.
Juniper Networks Contrail Networking
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues were discovered during external security research.
Important security issues resolved include:
The following software releases have been updated to resolve these specific issues: Contrail Networking 21.4.0, and all subsequent releases.
This issue is being tracked as CE-10037, CE-10122, CEM-17527, CEM-17528, CEM-20591, CEM-20592, CEM-21061, CEM-21062, CEM-21063, CEM-21064, CEM-21065, CEM-21066, CEM-21067, CEM-21068, CEM-21069, CEM-21070, CEM-23694, CEM-24657, CEM-24658, CEM-24659, CEM-24660, CEM-24661 and CEM-25547.Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
There are no known workarounds for these issues.
However, risk of malicious exploitation may be mitigated by limiting the exploitable attack surface of critical infrastructure networking equipment. Use access lists or firewall filters to limit access to the environment only from trusted, administrative networks or hosts.