CVE-2022-22242
Junos OS: Cross-site Scripting (XSS) vulnerability in J-Web
Record summary
CVE-2022-22242 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
A Cross-site Scripting (XSS) vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker to run malicious scripts reflected off of J-Web to the victim's browser in the context of their session within J-Web. This issue affects Juniper Networks Junos OS all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R2-S7, 19.4R3-S8; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S4; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R3; 21.4 versions prior to 21.4R2; 22.1 versions prior to 22.1R2.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 25, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 9, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Junos OSBrowse Juniper / Junos OS | VulnCheck | Version data not supplied | |
| CVE List | Before 19.1R3-S9 | affected | |
| 19.2 to < 19.2R3-S6 | affected | ||
| 19.3 to < 19.3R3-S7 | affected | ||
| 19.4 to < 19.4R2-S7, 19.4R3-S8 | affected | ||
| 20.1 to < 20.1R3-S5 | affected | ||
| 20.2 to < 20.2R3-S5 | affected | ||
| 20.3 to < 20.3R3-S5 | affected | ||
| 20.4 to < 20.4R3-S4 | affected | ||
| 21.1 to < 21.1R3-S4 | affected | ||
| 21.2 to < 21.2R3-S1 | affected | ||
| 21.3 to < 21.3R3 | affected | ||
| 21.4 to < 21.4R2 | affected | ||
| Showing 12 of 13 version ranges | |||
Nuclei templates
1ProjectDiscoveryMEDIUMJuniper Web Device Manager - Cross-Site ScriptingCVSS 6.1
Juniper Web Device Manager (J-Web) in Junos OS contains a cross-site scripting vulnerability. This can allow an unauthenticated attacker to run malicious scripts reflected off J-Web to the victim's browser in the context of their session within J-Web, which can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue affects all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R2-S7, 19.4R3-S8; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S4; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R3; 21.4 versions prior to 21.4R2; 22.1 versions prior to 22.1R2.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the targeted user's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Apply the latest security patches or updates provided by Juniper Networks to mitigate this vulnerability.
Source: ProjectDiscovery