Juniper patched nine critical flaws in Junos Space
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-47615 | GStreamer is a library for constructing graphs of media-handling components. GStreamer is a library for constructing graphs of media-handling components. An OOB-Write has been detected in the function gst_parse_vorbis_setup_packet within vorbis_parse.c. The integer size is read from the input file without proper validation. As a result, size can exceed the fixed size of the pad->vorbis_mode_sizes array (which size is 256). When this happens, the for loop overwrites the entire pad structure with 0s and 1s, affecting adjacent memory as well. This OOB-write can overwrite up to 380 bytes of memory beyond the boundaries of the pad->vorbis_mode_sizes array. This vulnerability is fixed in 1.24.10. NVD description · AI analysis pending | 8.6 | 1% |
| — | ||
| CVE-2025-59978 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to stor An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execute commands with the target's administrative permissions. This issue affects all versions of Junos Space before 24.1R4. NVD description · AI analysis pending | 9.4 | <1% |
| — |
Full article298 words · extracted from securityaffairs.com · click to collapse

Juniper fixed nearly 220 flaws in Junos OS, Junos Space, and Security Director, including nine critical bugs in Junos Space.
Juniper Networks released patches to address nearly 220 vulnerabilities in Junos OS, Junos Space, and Security Director, including nine critical flaws in Junos Space.
One of these flaws, tracked as CVE-2025-59978 (CVSS score of 9.0), is a critical Cross-Site Scripting (XSS) vulnerability in Juniper Networks Junos Space. It occurs due to improper neutralization of input during web page generation, allowing attackers to embed malicious script tags directly into web pages. When another user views these pages, the scripts execute with the victim’s administrative privileges, potentially allowing full control of the system. This flaw affects all Junos Space versions prior to 24.1R4, which includes the patch.
This type of vulnerability is particularly dangerous in administrative interfaces because it can lead to unauthorized configuration changes, data theft, or further network compromise.
Junos Space 24.1R4 Patch V1 fixes 162 vulnerabilities, including nine critical flaws and 24 cross-site scripting (XSS) bugs.
Junos Space 24.1R4 Patch V1 resolved 162 vulnerabilities, including nine critical issue. The two most severe vulnerabilities are:
- CVE-2025-59978 (CVSS score of 9.0): A cross-site scripting in Juniper Junos Space lets attackers inject script tags into web pages; when viewed these run with the viewer’s administrative privileges, enabling command execution and potential full system compromise. Affects versions before 24.1R4.
- CVE-2024-47615 (CVSS score of 8.6): A GStreamer OOB-write in
gst_parse_vorbis_setup_packetlets an attacker overwrite up to 380 bytes of memory due to unchecked input array size. Fixed in 1.24.10.
Juniper is not aware of any attacks in the wild exploiting these vulnerabilities, however, it recommends users to apply the patches as soon as possible.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Junos Space)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/183229/security/juniper-patched-nine-critical-flaws-in-junos-space.html