Junos OS: XPath Injection vulnerability in J-Web
Published Oct 18, 2022
4.3
MEDIUMCVSS 3.1
EPSS 0.48%
Description
An XPath Injection vulnerability due to Improper Input Validation in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to add an XPath command to the XPath stream, which may allow chaining to other unspecified vulnerabilities, leading to a partial loss of confidentiality. This issue affects Juniper Networks Junos OS: all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R2-S7, 19.4R3-S8; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S2; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R2-S2, 21.3R3; 21.4 versions prior to 21.4R1-S2, 21.4R2-S1, 21.4R3; 22.1 versions prior to 22.1R1-S1, 22.1R2.
Affected products
-
- Version 19.2StatusaffectedConstraints<19.2R3-S6
- Version 19.3StatusaffectedConstraints<19.3R3-S7
- Version 19.4StatusaffectedConstraints<19.4R2-S7, 19.4R3-S8
- Version 20.1StatusaffectedConstraints<20.1R3-S5
- Version 20.2StatusaffectedConstraints<20.2R3-S5
- Version 20.3StatusaffectedConstraints<20.3R3-S5
- Version 20.4StatusaffectedConstraints<20.4R3-S4
- Version 21.1StatusaffectedConstraints<21.1R3-S2
- Version 21.2StatusaffectedConstraints<21.2R3-S1
- Version 21.3StatusaffectedConstraints<21.3R2-S2, 21.3R3
- Version 21.4StatusaffectedConstraints<21.4R1-S2, 21.4R2-S1, 21.4R3
- Version 22.1StatusaffectedConstraints<22.1R1-S1, 22.1R2
- Version unspecifiedStatusaffectedConstraints<19.1R3-S9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Juniper Networks | Junos OS | n/a |
|
- < 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 21.1
- 21.1
- 21.1
- 21.1
- 21.1
- 21.1
- 21.1
- 21.1
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.3
- 21.3
- 21.3
- 21.3
- 21.3
- 21.3
- 21.3
- 21.4
- 21.4
- 21.4
- 21.4
- 21.4
- 21.4
- 21.4
- 22.1
- 22.1
- 22.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The following software releases have been updated to resolve this specific issue: Junos OS 19.1R3-S9, 19.2R3-S6, 19.3R3-S7, 19.4R2-S7, 19.4R3-S8, 20.1R3-S5, 20.2R3-S5, 20.3R3-S5, 20.4R3-S4, 21.1R3-S2, 21.2R3-S1, 21.3R2-S2, 21.3R3, 21.4R1-S2, 21.4R2-S1, 21.4R3, 22.1R1-S1, 22.1R2, 22.2R1, and all subsequent releases.
References (1)
- https://kb.juniper.net/JSA69899 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://kb.juniper.net/JSA69899 | Vendor Advisory |
Change history (0)
No recorded changes yet.