When Security Assertion Markup Language (SAML) authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly process invalid authentication certificates which could allow a malicious network-based user to access unauthorized data. This issue affects all Juniper Networks Mist Cloud UI versions prior to September 2 2020.
Solution:
Workaround:
The product does not check or incorrectly checks the revocation status of a certificate, which may cause it to use a certificate that has been compromised.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://kb.juniper.net/JSA11072 | vendor advisory |