Product Affected

This issue affects all versions of NorthStar Controller.
High
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Problem

Pivotal RabbitMQ is included with NorthStar Controller. Pivotal RabbitMQ versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a Denial of Service (DoS) attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing.
 

This issue affects Juniper Networks NorthStar Controller versions prior to 6.2.3.


Juniper SIRT is not aware of any malicious exploitation of this vulnerability.


This issue was discovered during external security research.


This issue has been assigned CVE-2019-11287.

Solution

The following software releases have been updated to resolve this specific issue: NorthStar Controller 6.2.3, and all subsequent releases.


This issue is being tracked as 1650603.


Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

A workaround is to manually disable the affected component by changing the configuration file /opt/northstar/thirdparty/rabbitmq/etc/rabbitmq/enabled_plugins from:

[rabbitmq_management].

to

[]

After saving the file, restart the NorthStar services to apply the change:

service northstar restart

Also to reduce the risk of exploitation use access controls or firewalls to limit access to the device only from trusted, administrative networks or hosts.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2023-01-11: Initial Publication

Related Information