PHP software included with Junos OS J-Web has been updated from 7.4.30 to 8.2.0 to resolve multiple vulnerabilities.
These issues affect Juniper Networks Junos OS versions prior to 23.2R1.
These issues affect devices with J-Web enabled.
[system services web-management]
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues were discovered during external security research.
Important security issues resolved include:
The following software releases have been updated to resolve these specific issues:
Junos OS 23.2R1, and all subsequent releases.
Thes issues are being tracked as 1698386
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Methods which may reduce, but not eliminate, the risk for exploitation of these problems, and which does not mitigate or resolve the underlying problems include:
• Using access lists or firewall filters to limit access to the device only from trusted hosts.
• Disabling J-Web
• Limit access to J-Web from only trusted networks
2023-07-12: Initial Publication