Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gr2q-rxqg-mrrq

Опубликовано: 11 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 4.2
CVSS3: 6.3

Описание

An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to access sensitive information.

When another user performs a specific operation, sensitive information is stored as plain text in a specific log file, so that a high-privileged attacker has access to this information. This issue affects:

Junos OS:

  • All versions before 22.1R2-S2,
  • 22.1R3 and later versions,
  • 22.2 versions before 22.2R2-S1, 22.2R3,
  • 22.3 versions before 22.3R1-S2, 22.3R2;

Junos OS Evolved:

  • All versions before before 22.1R3-EVO,
  • 22.2-EVO versions before 22.2R2-S1-EVO, 22.2R3-EVO,
  • 22.3-EVO versions before 22.3R1-S1-EVO, 22.3R2-EVO.

An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to access sensitive information.

When another user performs a specific operation, sensitive information is stored as plain text in a specific log file, so that a high-privileged attacker has access to this information. This issue affects:

Junos OS:

  • All versions before 22.1R2-S2,
  • 22.1R3 and later versions,
  • 22.2 versions before 22.2R2-S1, 22.2R3,
  • 22.3 versions before 22.3R1-S2, 22.3R2;

Junos OS Evolved:

  • All versions before before 22.1R3-EVO,
  • 22.2-EVO versions before 22.2R2-S1-EVO, 22.2R3-EVO,
  • 22.3-EVO versions before 22.3R1-S1-EVO, 22.3R2-EVO.

EPSS

Процентиль: 21%
0.00067
Низкий

4.2 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 6.3
nvd
больше 1 года назад

An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to access sensitive information. When another user performs a specific operation, sensitive information is stored as plain text in a specific log file, so that a high-privileged attacker has access to this information. This issue affects: Junos OS: * All versions before 21.2R3-S9; * 21.4 versions before 21.4R3-S9; * 22.2 versions before 22.2R2-S1, 22.2R3; * 22.3 versions before 22.3R1-S1, 22.3R2; Junos OS Evolved: * All versions before before 22.1R3-EVO; * 22.2-EVO versions before 22.2R2-S1-EVO, 22.2R3-EVO; * 22.3-EVO versions before 22.3R1-S1-EVO, 22.3R2-EVO.

CVSS3: 6.3
fstec
больше 1 года назад

Уязвимость операционных систем Juniper Networks Junos OS и Junos OS Evolved, связанная с раскрытием информации через регистрационные файлы, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 21%
0.00067
Низкий

4.2 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-532