CVSS: v3.1: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Multiple vulnerabilities have been resolved in nginx software included with Juniper Networks Junos OS by upgrading nginx to version 1.22.1 or by applying specific fixes.
For a system to be affected by these issues it needs to be configured with at least one of: webapi, or grpc telemetry (with Junos 23.4 or later).
This issue affects Junos OS:
For a system to be affected by this issue it needs to be configured with at least one of:[ system services webapi ]or[ system services extension-service request-response grpc ]
Important security issues resolved include:
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was discovered during external security research.
The following software releases have been updated to resolve this specific issue: 21.4R3-S8, 22.2R3-S5*, 22.3R3-S3, 22.4R3-S4, 23.2R2-S2, 23.4R2-S1, 24.2R1, and all subsequent releases.(* future release)
This issue is being tracked as 1805233 and 1777464 which are visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
There are no known workarounds for this issue.To reduce the risk of exploitation use access lists or firewall filters to limit access to the device only from trusted, administrative networks or hosts.
2024-10-09: Initial Publication