CVE Vulnerabilities

CVE-2023-36844

PHP External Variable Modification

Published: Aug 17, 2023 | Modified: Oct 02, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables.

Using a crafted request an attacker is able to modify

certain PHP environment variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on EX Series:

  • All versions prior to 20.4R3-S9;
  • 21.1 versions 21.1R1 and later;
  • 21.2 versions prior to 21.2R3-S7;
  • 21.3 versions

prior to

21.3R3-S5;

  • 21.4 versions

prior to

21.4R3-S5;

  • 22.1 versions

prior to

22.1R3-S4;

  • 22.2 versions

prior to

22.2R3-S2;

  • 22.3 versions

prior to 22.3R3-S1;

  • 22.4 versions

prior to

22.4R2-S2, 22.4R3;

  • 23.2 versions prior to

23.2R1-S1, 23.2R2.

Weakness

A PHP application does not properly protect against the modification of variables from external sources, such as query parameters or cookies. This can expose the application to numerous weaknesses that would not exist otherwise.

Affected Software

Name Vendor Start Version End Version
Junos Juniper * 20.4 (excluding)
Junos Juniper 20.4 (including) 20.4 (including)
Junos Juniper 20.4-r1 (including) 20.4-r1 (including)
Junos Juniper 20.4-r1-s1 (including) 20.4-r1-s1 (including)
Junos Juniper 20.4-r2 (including) 20.4-r2 (including)
Junos Juniper 20.4-r2-s1 (including) 20.4-r2-s1 (including)
Junos Juniper 20.4-r2-s2 (including) 20.4-r2-s2 (including)
Junos Juniper 20.4-r3 (including) 20.4-r3 (including)
Junos Juniper 20.4-r3-s1 (including) 20.4-r3-s1 (including)
Junos Juniper 20.4-r3-s2 (including) 20.4-r3-s2 (including)
Junos Juniper 20.4-r3-s3 (including) 20.4-r3-s3 (including)
Junos Juniper 20.4-r3-s4 (including) 20.4-r3-s4 (including)
Junos Juniper 20.4-r3-s5 (including) 20.4-r3-s5 (including)
Junos Juniper 20.4-r3-s6 (including) 20.4-r3-s6 (including)
Junos Juniper 20.4-r3-s7 (including) 20.4-r3-s7 (including)
Junos Juniper 21.1-r1 (including) 21.1-r1 (including)
Junos Juniper 21.1-r1-s1 (including) 21.1-r1-s1 (including)
Junos Juniper 21.1-r2 (including) 21.1-r2 (including)
Junos Juniper 21.1-r2-s1 (including) 21.1-r2-s1 (including)
Junos Juniper 21.1-r2-s2 (including) 21.1-r2-s2 (including)
Junos Juniper 21.1-r3 (including) 21.1-r3 (including)
Junos Juniper 21.1-r3-s1 (including) 21.1-r3-s1 (including)
Junos Juniper 21.1-r3-s2 (including) 21.1-r3-s2 (including)
Junos Juniper 21.1-r3-s3 (including) 21.1-r3-s3 (including)
Junos Juniper 21.1-r3-s4 (including) 21.1-r3-s4 (including)
Junos Juniper 21.1-r3-s5 (including) 21.1-r3-s5 (including)
Junos Juniper 21.2 (including) 21.2 (including)
Junos Juniper 21.2-r1 (including) 21.2-r1 (including)
Junos Juniper 21.2-r1-s1 (including) 21.2-r1-s1 (including)
Junos Juniper 21.2-r1-s2 (including) 21.2-r1-s2 (including)
Junos Juniper 21.2-r2 (including) 21.2-r2 (including)
Junos Juniper 21.2-r2-s1 (including) 21.2-r2-s1 (including)
Junos Juniper 21.2-r2-s2 (including) 21.2-r2-s2 (including)
Junos Juniper 21.2-r3 (including) 21.2-r3 (including)
Junos Juniper 21.2-r3-s1 (including) 21.2-r3-s1 (including)
Junos Juniper 21.2-r3-s2 (including) 21.2-r3-s2 (including)
Junos Juniper 21.2-r3-s3 (including) 21.2-r3-s3 (including)
Junos Juniper 21.2-r3-s4 (including) 21.2-r3-s4 (including)
Junos Juniper 21.2-r3-s5 (including) 21.2-r3-s5 (including)
Junos Juniper 21.3 (including) 21.3 (including)
Junos Juniper 21.3-r1 (including) 21.3-r1 (including)
Junos Juniper 21.3-r1-s1 (including) 21.3-r1-s1 (including)
Junos Juniper 21.3-r1-s2 (including) 21.3-r1-s2 (including)
Junos Juniper 21.3-r2 (including) 21.3-r2 (including)
Junos Juniper 21.3-r2-s1 (including) 21.3-r2-s1 (including)
Junos Juniper 21.3-r2-s2 (including) 21.3-r2-s2 (including)
Junos Juniper 21.3-r3 (including) 21.3-r3 (including)
Junos Juniper 21.3-r3-s1 (including) 21.3-r3-s1 (including)
Junos Juniper 21.3-r3-s2 (including) 21.3-r3-s2 (including)
Junos Juniper 21.3-r3-s3 (including) 21.3-r3-s3 (including)
Junos Juniper 21.3-r3-s4 (including) 21.3-r3-s4 (including)
Junos Juniper 21.4 (including) 21.4 (including)
Junos Juniper 21.4-r1 (including) 21.4-r1 (including)
Junos Juniper 21.4-r1-s1 (including) 21.4-r1-s1 (including)
Junos Juniper 21.4-r1-s2 (including) 21.4-r1-s2 (including)
Junos Juniper 21.4-r2 (including) 21.4-r2 (including)
Junos Juniper 21.4-r2-s1 (including) 21.4-r2-s1 (including)
Junos Juniper 21.4-r2-s2 (including) 21.4-r2-s2 (including)
Junos Juniper 21.4-r3 (including) 21.4-r3 (including)
Junos Juniper 21.4-r3-s1 (including) 21.4-r3-s1 (including)
Junos Juniper 21.4-r3-s2 (including) 21.4-r3-s2 (including)
Junos Juniper 21.4-r3-s3 (including) 21.4-r3-s3 (including)
Junos Juniper 21.4-r3-s4 (including) 21.4-r3-s4 (including)
Junos Juniper 22.1-r1 (including) 22.1-r1 (including)
Junos Juniper 22.1-r1-s1 (including) 22.1-r1-s1 (including)
Junos Juniper 22.1-r1-s2 (including) 22.1-r1-s2 (including)
Junos Juniper 22.1-r2 (including) 22.1-r2 (including)
Junos Juniper 22.1-r2-s1 (including) 22.1-r2-s1 (including)
Junos Juniper 22.1-r2-s2 (including) 22.1-r2-s2 (including)
Junos Juniper 22.1-r3 (including) 22.1-r3 (including)
Junos Juniper 22.1-r3-s1 (including) 22.1-r3-s1 (including)
Junos Juniper 22.1-r3-s2 (including) 22.1-r3-s2 (including)
Junos Juniper 22.2-r1 (including) 22.2-r1 (including)
Junos Juniper 22.2-r1-s1 (including) 22.2-r1-s1 (including)
Junos Juniper 22.2-r1-s2 (including) 22.2-r1-s2 (including)
Junos Juniper 22.2-r2 (including) 22.2-r2 (including)
Junos Juniper 22.2-r2-s1 (including) 22.2-r2-s1 (including)
Junos Juniper 22.2-r2-s2 (including) 22.2-r2-s2 (including)
Junos Juniper 22.2-r3 (including) 22.2-r3 (including)
Junos Juniper 22.2-r3-s1 (including) 22.2-r3-s1 (including)
Junos Juniper 22.3-r1 (including) 22.3-r1 (including)
Junos Juniper 22.3-r1-s1 (including) 22.3-r1-s1 (including)
Junos Juniper 22.3-r1-s2 (including) 22.3-r1-s2 (including)
Junos Juniper 22.3-r2 (including) 22.3-r2 (including)
Junos Juniper 22.3-r2-s1 (including) 22.3-r2-s1 (including)
Junos Juniper 22.4-r1 (including) 22.4-r1 (including)
Junos Juniper 22.4-r1-s1 (including) 22.4-r1-s1 (including)
Junos Juniper 22.4-r1-s2 (including) 22.4-r1-s2 (including)
Junos Juniper 22.4-r2 (including) 22.4-r2 (including)

Potential Mitigations

References