Multiple vulnerabilities in third party software used in Juniper Networks Cloud Native Contrail Networking have been resolved in release R22.3.
These issues affect Juniper Networks Cloud Native Contrail Networking versions after R22.1 and prior to R22.3.
These issues were discovered during external security research.
Important security issues resolved include:
The following software releases have been updated to resolve these specific issues: Cloud Native Contrail Networking R22.3, and all subsequent releases.
These issues are being tracked as CN2-5003.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Software Releases, patches and updates are available at https://support.juniper.net/support/downloads/.
2022-10-12: Initial Publication. 2023-01-03: Clarified that versions prior to R22.1 are unaffected.