CVE-2017-10617
Summary
| CVE | CVE-2017-10617 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-13 17:29:00 UTC |
| Updated | 2023-01-30 18:59:00 UTC |
| Description | The ifmap service that comes bundled with Contrail has an XML External Entity (XXE) vulnerability that may allow an attacker to retrieve sensitive system files. Affected releases are Juniper Networks Contrail 2.2 prior to 2.21.4; 3.0 prior to 3.0.3.4; 3.1 prior to 3.1.4.0; 3.2 prior to 3.2.5.0. CVE-2017-10616 and CVE-2017-10617 can be chained together and have a combined CVSSv3 score of 5.8 (AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N). |
Risk And Classification
Problem Types: CWE-611
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Juniper | Contrail | All | All | All | All |
| Application | Juniper | Contrail | 2.2 | All | All | All |
| Application | Juniper | Contrail | 3.0 | All | All | All |
| Application | Juniper | Contrail | 3.1 | All | All | All |
| Application | Juniper | Contrail | 3.2 | All | All | All |
| Application | Juniper | Contrail | 2.2 | All | All | All |
| Application | Juniper | Contrail | 3.0 | All | All | All |
| Application | Juniper | Contrail | 3.1 | All | All | All |
| Application | Juniper | Contrail | 3.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2017-10 Security Bulletin: Contrail: hard coded credentials (CVE-2017-10616) and XML External Entity (XXE) vulnerability (CVE-2017-10617) - Juniper Networks | CONFIRM | kb.juniper.net | Vendor Advisory |
| Juniper Contrail - The XML External Entity (XXE) vulnerability (CVE-2017-10617) · Advisory · orangecertcc/security-research · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Guillaume TEISSIER / Orange for responsibly reporting this vulnerability.
There are currently no legacy QID mappings associated with this CVE.