CVE-2019-0017: Junos Space: Unrestricted file upload vulnerability
Published Jan 15, 2019
·Updated
The Junos Space application, which allows Device Image files to be uploaded, has insufficient validity checking which may allow uploading of malicious images or scripts, or other content types. Affected releases are Juniper Networks Junos Space versions prior to 18.3R1.
Affected Software
23 affected components
Juniper Junos Space=13.3-r1
Juniper Junos Space=13.3-r2
Juniper Junos Space=13.3-r3
Juniper Junos Space=13.3-r4
Juniper Junos Space=14.1
Juniper Junos Space=14.1-r1
Juniper Junos Space=14.1-r2
Juniper Junos Space=14.1-r3
Juniper Junos Space=15.1-r1
Juniper Junos Space=15.1-r2
Juniper Junos Space=15.1-r3
Juniper Junos Space=15.1-r4
Juniper Junos Space=15.2
Juniper Junos Space=15.2-r1
Juniper Junos Space=15.2-r2
Juniper Junos Space=16.1
Juniper Junos Space=16.1-r1
Juniper Junos Space=16.1-r2
Juniper Junos Space=16.1-r3
Juniper Junos Space=17.1-r1
Juniper Junos Space=17.2-r1.4
Juniper Junos Space=18.1-r1
Juniper Junos Space=18.2-r1
Event History
Jan 15, 2019
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-0017?
The CVE-2019-0017 vulnerability has a high severity rating due to insufficient validation checks allowing malicious content uploads.
2
How do I fix CVE-2019-0017?
To fix CVE-2019-0017, upgrade to Junos Space version 18.3R1 or later.
3
Which versions of Junos Space are affected by CVE-2019-0017?
Junos Space versions prior to 18.3R1 are affected by CVE-2019-0017.
4
What risks are associated with CVE-2019-0017?
CVE-2019-0017 poses risks of unauthorized malicious file uploads that could compromise the environment.
5
Is there a patch available for CVE-2019-0017?
Yes, a patch is available in the form of an upgrade to Junos Space version 18.3R1 or later.