2024 Juniper Networks — customer support portal permission bug exposed cross-customer device and contract metadata (Feb)
Data compromised
Device inventory and entitlement metadata indirectly revealing patching/support posture; not a confirmed mass credentials leak
Technical writeup
Krebs on Security reported that after a logged-in customer searched Juniper’s rebuilt Salesforce-backed support portal, overly broad object permissions let them pull device model, serial, warranty, service-contract and coarse deployment clues for other customers’ hardware—discovered by a teenage intern and reported upward. Juniper told reporters the issue followed a recent portal upgrade, was promptly remediated, and that it saw no reason to believe traditional PII had leaked. The Register’s infosec roundup independently summarized the same Krebs findings for enterprise readers.
Root cause
Authorization/tenant isolation misconfiguration in customer support SaaS after portal migration