When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle SAML responses, allowing a remote attacker to modify a valid SAML response without invalidating its cryptographic signature to bypass SAML authentication security controls. This issue affects all Juniper Networks Mist Cloud UI versions prior to September 2 2020.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:NJuniper Mist Cloud Ui
APPJuniper< 2020-09-02
Powiązane podatności
When Security Assertion Markup Language (SAML) authentication is enabled, Juniper Networks Mist Cloud UI might...
When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle child elements in...
RCE przez modyfikację zmiennej PHP w J-Web Juniper Junos OS (EX/SRX)
Juniper ScreenOS — backdoor umożliwiający pominięcie uwierzytelnienia (SSH/Telnet)
Słabe wymagania hasła w Juniper Networks CTP OS — przejęcie urządzenia