Back

HIGH

Juniper Networks Mist Cloud UI: SAML authentication attribute elements handling vulnerability.

Published Oct 16, 2020

Description

When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle child elements in SAML responses, allowing a remote attacker to modify a valid SAML response without invalidating its cryptographic signature to bypass SAML authentication security controls. This issue affects all Juniper Networks Mist Cloud UI versions prior to September 2 2020.

Affected products

Remediation

Vendor solution

Mist Cloud UI has been updated on September 2 2020 to resolve this specific issue.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner juniper
Published Oct 16, 2020
Updated Sep 16, 2024
Reserved Nov 4, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a