CVE-2018-0047
Summary
| CVE | CVE-2018-0047 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-10 18:29:00 UTC |
| Updated | 2019-10-09 23:31:00 UTC |
| Description | A persistent cross-site scripting vulnerability in the UI framework used by Junos Space Security Director may allow authenticated users to inject persistent and malicious scripts. This may allow stealing of information or performing actions as a different user when other users access the Security Director web interface. This issue affects all versions of Juniper Networks Junos Space Security Director prior to 17.2R2. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Juniper | Junos Space | 13.3 | r1 | All | All |
| Operating System | Juniper | Junos Space | 13.3 | r2 | All | All |
| Operating System | Juniper | Junos Space | 14.1 | r1 | All | All |
| Operating System | Juniper | Junos Space | 14.1 | r2 | All | All |
| Operating System | Juniper | Junos Space | 14.1 | r3 | All | All |
| Operating System | Juniper | Junos Space | 15.1 | r1 | All | All |
| Operating System | Juniper | Junos Space | 15.1 | r2 | All | All |
| Operating System | Juniper | Junos Space | 15.1 | r3 | All | All |
| Operating System | Juniper | Junos Space | 15.1 | r4 | All | All |
| Operating System | Juniper | Junos Space | 15.2 | r1 | All | All |
| Operating System | Juniper | Junos Space | 15.2 | r2 | All | All |
| Operating System | Juniper | Junos Space | 16.1 | r1 | All | All |
| Operating System | Juniper | Junos Space | 16.1 | r2 | All | All |
| Operating System | Juniper | Junos Space | 16.1 | r3 | All | All |
| Operating System | Juniper | Junos Space | 17.1 | r1 | All | All |
| Operating System | Juniper | Junos Space | 17.2 | r1 | All | All |
| Operating System | Juniper | Junos Space | 13.3 | r1 | All | All |
| Operating System | Juniper | Junos Space | 13.3 | r2 | All | All |
| Operating System | Juniper | Junos Space | 14.1 | r1 | All | All |
| Operating System | Juniper | Junos Space | 14.1 | r2 | All | All |
| Operating System | Juniper | Junos Space | 14.1 | r3 | All | All |
| Operating System | Juniper | Junos Space | 15.1 | r1 | All | All |
| Operating System | Juniper | Junos Space | 15.1 | r2 | All | All |
| Operating System | Juniper | Junos Space | 15.1 | r3 | All | All |
| Operating System | Juniper | Junos Space | 15.1 | r4 | All | All |
| Operating System | Juniper | Junos Space | 15.2 | r1 | All | All |
| Operating System | Juniper | Junos Space | 15.2 | r2 | All | All |
| Operating System | Juniper | Junos Space | 16.1 | r1 | All | All |
| Operating System | Juniper | Junos Space | 16.1 | r2 | All | All |
| Operating System | Juniper | Junos Space | 16.1 | r3 | All | All |
| Operating System | Juniper | Junos Space | 17.1 | r1 | All | All |
| Operating System | Juniper | Junos Space | 17.2 | r1 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2018-10 Security Bulletin: Junos Space Security Director: XSS vulnerability in web administration (CVE-2018-0047) - Juniper Networks | CONFIRM | kb.juniper.net | Vendor Advisory |
| Juniper Junos Space Security Director Input Validation Flaw Lets Remote Users Conduct Cross-Site Scripting Attacks - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Marcel Bilal of IT-Dienstleistungszentrum Berlin
There are currently no legacy QID mappings associated with this CVE.