CVE-2023-45140
Summary
| CVE | CVE-2023-45140 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-11-08 16:15:00 UTC |
| Updated | 2023-11-16 18:50:00 UTC |
| Description | The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. SCP and SFTP plugins don't honor group-based JIT MFA. Establishing a SCP/SFTP connection through The Bastion via a group access where MFA is enforced does not ask for additional factor. This abnormal behavior only applies to per-group-based JIT MFA. Other MFA setup types, such as Immediate MFA, JIT MFA on a per-plugin basis and JIT MFA on a per-account basis are not affected. This issue has been patched in version 3.14.15. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Ovh |
The-bastion |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| Group-based and account-based JIT MFA bypass on scp and sftp · Advisory · ovh/the-bastion · GitHub |
|
github.com |
|
| Release v3.14.15 · ovh/the-bastion · GitHub |
|
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.