Multiple vulnerabilities have been found in the J-Web component of Juniper Networks Junos OS. One or more of these issues could lead to unauthorized local file access, cross-site scripting attacks, path injection and traversal, or local file inclusion.
A weak cipher used for checking file integrity was also reported, but had been resolved in earlier releases of Junos OS.
These issues affect Juniper Networks Junos OS:
These issues were discovered during external security research.The specific issues reported and resolved are listed below:
The following software releases have been updated to resolve these specific issues: Junos OS 19.1R3-S9, 19.2R3-S6, 19.3R3-S7, 19.4R3-S9, 20.1R3-S5, 20.2R3-S5, 20.3R3-S5, 20.4R3-S4, 21.1R3-S2, 21.3R3, 21.4R3, 22.1R2, 22.2R1, and all subsequent releases.
These issues are being tracked as 1656805, 1656806, 1656808, 1656809, 1656810 and 1656811 which are visible on the Customer Support website.Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Software Releases, patches and updates are available at https://support.juniper.net/support/downloads/.
2022-10-12: Initial Publication.