Multiple Improper Authentication vulnerabilities in the J-Web component of Juniper Networks Junos OS have been resolved through the application of specific fixes to address each vulnerability.
By chaining exploitation of these vulnerabilities, an unauthenticated network-based attacker may be able to read any file belonging to user "nobody", including sensitive session information.
These issues affect Juniper Networks Junos OS:
These issues were discovered during external security research.
The specific issues reported and resolved are listed below:
The following software releases have been updated to resolve these specific issues: Junos OS 19.4R3-S11, 20.2R3-S7, 20.4R3-S6, 21.2R3-S4, 21.3R3-S3, 21.4R3-S3, 22.1R3-S1, 22.2R2-S1, 22.2R3, 22.3R1-S2, 22.3R2, 22.4R1, and all subsequent releases.
These issues are being tracked as 1698072 and 1698075
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
2023-04-12: Initial Publication.