CVE Vulnerabilities

CVE-2024-39532

Insertion of Sensitive Information into Log File

Published: Jul 11, 2024 | Modified: Jan 22, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to access sensitive information.

When another user performs a specific operation, sensitive information is stored as plain text in a specific log file, so that a high-privileged attacker has access to this information. This issue affects:

Junos OS:

  • All versions before 21.2R3-S9;

21.4 versions before 21.4R3-S9;

  • 22.2 versions before 22.2R2-S1, 22.2R3;
  • 22.3 versions before 22.3R1-S1, 22.3R2;

Junos OS Evolved:

  • All versions before before 22.1R3-EVO;
  • 22.2-EVO versions before 22.2R2-S1-EVO, 22.2R3-EVO;
  • 22.3-EVO versions before 22.3R1-S1-EVO, 22.3R2-EVO.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
JunosJuniper*21.2 (excluding)
JunosJuniper21.2 (including)21.2 (including)
JunosJuniper21.2-r1 (including)21.2-r1 (including)
JunosJuniper21.2-r1-s1 (including)21.2-r1-s1 (including)
JunosJuniper21.2-r1-s2 (including)21.2-r1-s2 (including)
JunosJuniper21.2-r2 (including)21.2-r2 (including)
JunosJuniper21.2-r2-s1 (including)21.2-r2-s1 (including)
JunosJuniper21.2-r2-s2 (including)21.2-r2-s2 (including)
JunosJuniper21.2-r3 (including)21.2-r3 (including)
JunosJuniper21.2-r3-s1 (including)21.2-r3-s1 (including)
JunosJuniper21.2-r3-s2 (including)21.2-r3-s2 (including)
JunosJuniper21.2-r3-s3 (including)21.2-r3-s3 (including)
JunosJuniper21.2-r3-s4 (including)21.2-r3-s4 (including)
JunosJuniper21.2-r3-s5 (including)21.2-r3-s5 (including)
JunosJuniper21.2-r3-s6 (including)21.2-r3-s6 (including)
JunosJuniper21.2-r3-s7 (including)21.2-r3-s7 (including)
JunosJuniper21.2-r3-s8 (including)21.2-r3-s8 (including)
JunosJuniper21.4 (including)21.4 (including)
JunosJuniper21.4-r1 (including)21.4-r1 (including)
JunosJuniper21.4-r1-s1 (including)21.4-r1-s1 (including)
JunosJuniper21.4-r1-s2 (including)21.4-r1-s2 (including)
JunosJuniper21.4-r2 (including)21.4-r2 (including)
JunosJuniper21.4-r2-s1 (including)21.4-r2-s1 (including)
JunosJuniper21.4-r2-s2 (including)21.4-r2-s2 (including)
JunosJuniper21.4-r3 (including)21.4-r3 (including)
JunosJuniper21.4-r3-s1 (including)21.4-r3-s1 (including)
JunosJuniper21.4-r3-s2 (including)21.4-r3-s2 (including)
JunosJuniper21.4-r3-s3 (including)21.4-r3-s3 (including)
JunosJuniper21.4-r3-s4 (including)21.4-r3-s4 (including)
JunosJuniper21.4-r3-s5 (including)21.4-r3-s5 (including)
JunosJuniper21.4-r3-s6 (including)21.4-r3-s6 (including)
JunosJuniper21.4-r3-s7 (including)21.4-r3-s7 (including)
JunosJuniper21.4-r3-s8 (including)21.4-r3-s8 (including)
JunosJuniper22.2 (including)22.2 (including)
JunosJuniper22.2-r1 (including)22.2-r1 (including)
JunosJuniper22.2-r1-s1 (including)22.2-r1-s1 (including)
JunosJuniper22.2-r1-s2 (including)22.2-r1-s2 (including)
JunosJuniper22.2-r2 (including)22.2-r2 (including)
JunosJuniper22.2-r3 (including)22.2-r3 (including)
JunosJuniper22.3 (including)22.3 (including)
JunosJuniper22.3-r1 (including)22.3-r1 (including)
JunosJuniper22.3-r2 (including)22.3-r2 (including)
Junos_os_evolvedJuniper22.1 (including)22.1 (including)
Junos_os_evolvedJuniper22.1-r1 (including)22.1-r1 (including)
Junos_os_evolvedJuniper22.1-r1-s1 (including)22.1-r1-s1 (including)
Junos_os_evolvedJuniper22.1-r1-s2 (including)22.1-r1-s2 (including)
Junos_os_evolvedJuniper22.1-r2 (including)22.1-r2 (including)
Junos_os_evolvedJuniper22.1-r2-s1 (including)22.1-r2-s1 (including)
Junos_os_evolvedJuniper22.2 (including)22.2 (including)
Junos_os_evolvedJuniper22.2-r1 (including)22.2-r1 (including)
Junos_os_evolvedJuniper22.2-r1-s1 (including)22.2-r1-s1 (including)
Junos_os_evolvedJuniper22.2-r1-s2 (including)22.2-r1-s2 (including)
Junos_os_evolvedJuniper22.2-r2 (including)22.2-r2 (including)
Junos_os_evolvedJuniper22.2-r3 (including)22.2-r3 (including)
Junos_os_evolvedJuniper22.3 (including)22.3 (including)
Junos_os_evolvedJuniper22.3-r1 (including)22.3-r1 (including)
Junos_os_evolvedJuniper22.3-r2 (including)22.3-r2 (including)

Potential Mitigations

References