When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle SAML responses, allowing a remote attacker to modify a valid SAML response without invalidating its cryptographic signature to bypass SAML authentication security controls. This issue affects all Juniper Networks Mist Cloud UI versions prior to September 2 2020.
Mist Cloud UI has been updated on September 2 2020 to resolve this specific issue.
No workarounds are required since the issue has been resolved in the Mist cloud UI.
| Product | Vulnerable range | Fixed version | Advisory |
|---|---|---|---|
| Juniper Networks MIST Cloud UI | >=unspecified<09/02/2020 | 09/02/2020 | advisory ↗ |