Product Affected

These issues affect Junos OS 21.4, 22.1, 22.2, 22.3, 22.4, 23.2, 23.4.
High

CVSS: v3.1: 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

Problem

PHP software included with Juniper Networks Junos OS J-Web has been updated to resolve multiple vulnerabilities.

These issues affect Juniper Networks Junos OS:

  • All versions before 21.4R3-S8,
  • from 22.1 before 22.1R3-S6,
  • from 22.2 before 22.2R3-S4,
  • from 22.3 before 22.3R3-S3,
  • from 22.4 before 22.4R3-S2,
  • from 23.2 before 23.2R2-S2,
  • from 23.4 before 23.4R1-S2, 23.4R2.

Required configuration for exposure:

These issues affect devices with J-Web enabled.

[system services web-management]

Important security issues resolved include:

CVECVSSSummary
CVE-2023-05676.2 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password database, it may lead to an application allowing any password for this entry as valid. 
CVE-2023-06627.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space. 
CVE-2023-38237.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down. 
CVE-2023-38240.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N)In PHP version 8.0.* before 8.0.30,  8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading potentially to memory corruption or RCE. 
CVE-2023-05688.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolving paths with lengths close to system MAXPATHLEN setting, this may lead to the byte after the allocated buffer being overwritten with NUL value, which might lead to unauthorized data access or modification.  Only 21.4R3-S7 and older versions of Junos OS are affected by this vulnerability.

Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.

These issues were discovered by a third-party upstream provider.

Solution

The following software releases have been updated to resolve these specific issues:

Junos OS: 21.4R3-S8, 22.1R3-S6, 22.2R3-S4, 22.3R3-S3, 22.4R3-S2, 23.2R2-S2, 23.4R1-S2, 23.4R2, 24.2R1, and all subsequent releases.

Note regarding CVE-2023-0568: Only 21.4R3-S7 and older versions of Junos OS are affected by this vulnerability.
Note regarding CVE-2023-3824. This issue does not affect any version of Junos OS. The CVE is included for informational purposes only. The effective CVSS rating is 0.0.

These issues are being tracked as 1725808 which is visible on the Customer Support website.

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

There are no known workarounds for these issues.

To reduce the risk of exploitation disable J-Web, or limit access to only trusted hosts.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2024-10-09: Initial Publication

Related Information