CVE-2017-10612
Summary
| CVE | CVE-2017-10612 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-13 17:29:00 UTC |
| Updated | 2019-10-09 23:21:00 UTC |
| Description | A persistent site scripting vulnerability in Juniper Networks Junos Space allows users who can change certain configuration to implant malicious Javascript or HTML which may be used to steal information or perform actions as other Junos Space users or administrators. Affected releases are Juniper Networks Junos Space all versions prior to 17.1R1. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Juniper | Junos Space | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Juniper Networks JUNOS Space CVE-2017-10612 HTML Injection Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| 2017-10 Security Bulletin: Junos Space: Multiple vulnerabilities resolved in 17.1R1 release - Juniper Networks | CONFIRM | kb.juniper.net | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.