Path traversal in Juniper Junos OS - CVE-2020-1606
Published: January 10, 2020
Juniper Junos OS
Detailed vulnerability description
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote authenticated J-web user can send a specially crafted HTTP request and read files with "world" readable permission and delete files with "world" writeable permission.