An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator. A specific invocation of the emit_debug_note method in webauth_operation.php will echo back the data it receives. This issue affects Juniper Networks Junos OS on SRX Series and EX Series: * All versions earlier than 20.4R3-S10; * 21.2 versions earlier than 21.2R3-S8; * 21.4 versions earlier than 21.4R3-S6; * 22.1 versions earlier than 22.1R3-S5; * 22.2 versions earlier than 22.2R3-S3; * 22.3 versions earlier than 22.3R3-S2; * 22.4 ve
The following software releases have been updated to resolve this specific issue: 20.4R3-S10*, 21.2R3-S8*, 21.4R3-S6*, 22.1R3-S5*, 22.2R3-S3*, 22.3R3-S2*, 22.4R3-S1*, 23.2R2*, 23.4R2*, 24.2R1*, and all subsequent releases. * Pending Publication
Disable J-Web, or limit access to only trusted hosts and users.
| Product | Vulnerable range | Fixed version | Advisory |
|---|---|---|---|
| Juniper Networks Junos OS | <20.4R3-S10 | 20.4R3-S10 | advisory ↗ |
| Juniper Networks Junos OS | >=21.2<21.2R3-S8 | 21.2R3-S8 | advisory ↗ |
| Juniper Networks Junos OS | >=21.4<21.4R3-S6 | 21.4R3-S6 | advisory ↗ |
| Juniper Networks Junos OS | >=22.1<22.1R3-S5 | 22.1R3-S5 | advisory ↗ |
| Juniper Networks Junos OS | >=22.2<22.2R3-S3 | 22.2R3-S3 | advisory ↗ |
| Juniper Networks Junos OS | >=22.3<22.3R3-S2 | 22.3R3-S2 | advisory ↗ |
| Juniper Networks Junos OS | >=22.4<22.4R3-S1 | 22.4R3-S1 | advisory ↗ |
| Juniper Networks Junos OS | >=23.2<23.2R2 | 23.2R2 | advisory ↗ |
| Juniper Networks Junos OS | >=23.4<23.4R2 | 23.4R2 | advisory ↗ |