Juniper Junos SRX Web Authentication Cross Site Scripting Vulnerability
BID:68548
Info
Juniper Junos SRX Web Authentication Cross Site Scripting Vulnerability
| Bugtraq ID: | 68548 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3821 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2014 12:00AM |
| Updated: | Jul 11 2014 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Juniper Junos 12.1x47 Juniper Junos 12.1X46-D10 Juniper Junos 12.1X46 Juniper Junos 12.1X45-D20 Juniper Junos 12.1X45-D10 Juniper Junos 12.1X45 Juniper Junos 12.1X44-D32 Juniper Junos 12.1X44-D30 Juniper Junos 12.1X44-D26 Juniper Junos 12.1X44-D20 Juniper Junos 12.1X44 Juniper Junos 11.4R9 Juniper Junos 11.4R8 Juniper Junos 11.4R10-S1 Juniper Junos 11.4R10 Juniper Junos 11.4 |
| Not Vulnerable: |
Juniper Junos 12.1X47-D10 Juniper Junos 12.1X46-D20 Juniper Junos 12.1X45-D25 Juniper Junos 12.1X44-D34 Juniper Junos 11.4R11 |
Discussion
Juniper Junos SRX Web Authentication Cross Site Scripting Vulnerability
Juniper Junos is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Juniper Junos is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Solution / Fix
Juniper Junos SRX Web Authentication Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Juniper Junos SRX Web Authentication Cross Site Scripting Vulnerability
References:
References:
- 2014-07 Security Bulletin: Junos: XSS vulnerability in web authentication (webau (Juniper Networks)
- Juniper Networks Homepage (Juniper Networks)