Back

MEDIUM

Juniper ATP: API and device keys are logged in a world-readable permissions file

Published Jan 15, 2019

Description

On Juniper ATP, the API key and the device key are logged in a file readable by authenticated local users. These keys are used for performing critical operations on the WebUI interface. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.

Affected products

Remediation

Vendor solution

The following software release have been updated to resolve this specific issue: 5.0.3 and all subsequent releases. It is also recommended to change the device key after the upgrade.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner juniper
Published Jan 15, 2019
Updated Sep 16, 2024
Reserved Oct 11, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a