Multiple vulnerabilities have been resolved in Juniper Networks Contrail Service Orchestration (CSO), by updating third party software included with Contrail Service Orchestration (CSO) or by fixing vulnerabilities found during external security research.
These issues affect all versions of Juniper Networks Contrail Service Orchestration (CSO) prior to 6.3.0.
These issue were discovered during external security research.
Important security issues resolved include:
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
2023-01-11: Initial Publication
2023-01-17: CVE-2016-8625 and CVE-2016-8743 also resolved in CSO 6.3.0 via CXU-61263