CVE-2025-59984: Junos Space: Global Search is vulnerable to reflected cross-site script injection
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in Global Search that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This issue affects all versions of Junos Space before 24.1R4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59984?
CVE-2025-59984 has a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-59984?
To mitigate CVE-2025-59984, update your Juniper Networks Junos Space to version 24.1R4 or later.
What are the potential impacts of CVE-2025-59984?
The impact of CVE-2025-59984 includes the ability for attackers to execute unauthorized commands on behalf of another user.
Which versions of Junos Space are affected by CVE-2025-59984?
CVE-2025-59984 affects versions of Juniper Networks Junos Space prior to 24.1R4.
Is user input validation a recommended practice to prevent CVE-2025-59984?
Yes, implementing proper user input validation can help prevent vulnerabilities like CVE-2025-59984.