CVE-2021-31380 MEDIUM

CVE-2021-31380: SRC Series: A remote attacker sending a specially crafted query may cause the web server to disclose sensitive information

Vendor Juniper Networks
Product SRC Series
Weakness CWE-16
Published October 19, 2021
Last update September 16, 2024

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a specially crafted query to cause the web server to disclose sensitive information in the HTTP response which allows the attacker to obtain sensitive information.

Key dates

02Disclosure timeline

October 19, 2021 CVE published
September 16, 2024 Record updated