Multiple vulnerabilities have been resolved in Juniper Secure Analytics optional Applications (App).
These issues affect Juniper Networks Juniper Secure Analytics:
• Log Collector Application prior to version v1.8.4
• SOAR Plugin Application prior to version 5.3.1
• Deployment Intelligence Application prior to 3.0.16
• User Behavior Analytics Application add-on prior to 4.1.14• Pulse Application add-on prior to 2.2.15• Assistant Application add-on prior to 3.8.0
• Use Case Manager Application add-on prior to 3.9.0
• WinCollect Standalone Agent prior to 10.1.8• M7 Appliances prior to 4.0.0• Log Source Management App prior to 7.0.8
This issue was discovered during external security research.
body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
6.2 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
The following software releases have been updated to resolve these specific issues:
• Disconnected Log Collector App v1.8.4 and all subsequent releases.
• SOAR Plugin App 5.3.1 and all subsequent releases.
• Intelligence App 3.0.17 and all subsequent releases.
• Behavior Analytics App 4.1.14 and all subsequent releases.• Pulse App 2.2.15 and all subsequent releases.• Assistant App 3.8.1 and all subsequent releases.• Use Case Manager App 3.10.0 and all subsequent releases. • WinCollect Standalone Agent 10.1.9 and all subsequent releases. • M7 Appliances 4.0.0 ISO and all subsequent releases. • Log Source Management App 7.0.9 and all subsequent releases.
Note: Juniper SIRT's policy [juniper.net] is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
There are no known workarounds for these issues.
2024-01-31: Initial Publication. 2024-02-26: Use Case Manager Application vulnerability added. 2024-02-28: WinCollect Standalone Agent vulnerability added. 2024-03-23: M7 Appliances vulnerability added. 2024-04-24: Intelligence app update to 3.0.13 2024-05-08: Log Source Management app update to 7.0.9 2024-07-08: Intelligence app update to 3.0.14 2024-08-29: Use Case Manager app update to 3.10.0 2024-09-05: Assistant app update to 3.8.02024-10-28: Assistant app update to 3.8.12024-11-01: Intelligence app update to 3.0.152024-11-20: Pulse app update to 2.2.142025-03-06: Pulse app update to 2.2.152025-06-26: Intelligence app update to 3.0.17