Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-31380— SRC Series: A remote attacker sending a specially crafted query may cause the web server to disclose sensitive information

CVSS 5.3 · Medium EPSS 0.17% · P38
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-31380

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SRC Series: A remote attacker sending a specially crafted query may cause the web server to disclose sensitive information
Source: NVD (National Vulnerability Database)
Vulnerability Description
A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a specially crafted query to cause the web server to disclose sensitive information in the HTTP response which allows the attacker to obtain sensitive information.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
配置
Source: NVD (National Vulnerability Database)
Vulnerability Title
Red Hat JBoss Application Server 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Red Hat JBoss Application Server是美国红帽(Red Hat)公司的一款基于Java EE的开源的应用服务器。该产品具有启动超快、轻量、模块化设计、热部署和并行部署、简洁管理、域管理及第一类元件等特性。 JBoss Application Server of Juniper Networks 存在安全漏洞,远程攻击者可利用该漏洞通过发送一个特制的查询,使web服务器在HTTP响应中泄露敏感信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Juniper NetworksSRC Series unspecified ~ 4.12.0R5 -

II. Public POCs for CVE-2021-31380

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-31380

登录查看更多情报信息。

Same Patch Batch · Juniper Networks · 2021-10-19 · 42 CVEs total

CVE-2021-313499.8 CRITICALSession Smart Router: Authentication Bypass Vulnerability
CVE-2021-313858.8 HIGHJunos OS: J-Web: A path traversal vulnerability allows an authenticated attacker to elevat
CVE-2021-313728.8 HIGHJunos OS: J-Web allows a locally authenticated attacker to escalate their privileges to ro
CVE-2021-313738.0 HIGHJunos OS: SRX Series: Persistent XSS vulnerability in J-Web
CVE-2021-313558.0 HIGHJunos OS: Stored Cross-Site Scripting (XSS) vulnerability in captive portal
CVE-2021-313597.8 HIGHJunos OS and Junos OS Evolved: Local Privilege Escalation vulnerability
CVE-2021-313587.8 HIGHJunos OS Evolved: shell-injection vulnerabilities in evo_sftp UI wrapper script
CVE-2021-313577.8 HIGHJunos OS Evolved: shell-injection vulnerabilities in evo_tcpdump UI wrapper script
CVE-2021-313567.8 HIGHJunos OS Evolved: Multiple shell-injection vulnerabilities in EVO UI wrapper scripts
CVE-2021-313767.5 HIGHJunos OS: ACX Series: Packet Forwarding Engine manager (FXPC) process crashes when process
CVE-2021-313537.5 HIGHJunos OS and Junos OS Evolved: RPD core upon receipt of specific BGP update
CVE-2021-313747.5 HIGHJunos OS and Junos OS Evolved: RPD crash while processing a specially crafted BGP UPDATE o
CVE-2021-313517.5 HIGHJunos OS: MX Series: Receipt of specific packet on MS-MPC/MS-MIC causes line card reset
CVE-2021-313797.5 HIGHJunos OS: MX Series: MPC 7/8/9/10/11 cards with MAP-E: PFE halts when an attacker sends ma
CVE-2021-313507.5 HIGHJunos OS and Junos OS Evolved: Privilege escalation vulnerability in Juniper Extension Too
CVE-2021-313837.5 HIGHJunos OS and Junos OS Evolved: In Point to MultiPoint (P2MP) scenarios receipt of various
CVE-2021-02997.5 HIGHJunos OS: Kernel crash (vmcore) upon receipt of a malformed IPv6 packet
CVE-2021-313687.5 HIGHJunos OS: EX2300 Series, EX3400 Series, and ACX710 might become unresponsive if the out-of
CVE-2021-02967.4 HIGHCTPView: HSTS not being enforced on CTPView server.
CVE-2021-313847.2 HIGHJunos OS: SRX Series: Under a specific device configuration an attacker can access the dev

Showing top 20 of 42 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2021-31380

No comments yet


Leave a comment