CVE-2023-45140: Group-based JIT MFA bypass on scp and sftp in The Bastion

Published Nov 8, 2023
·
Updated

The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. SCP and SFTP plugins don't honor group-based JIT MFA. Establishing a SCP/SFTP connection through The Bastion via a group access where MFA is enforced does not ask for additional factor. This abnormal behavior only applies to per-group-based JIT MFA. Other MFA setup types, such as Immediate MFA, JIT MFA on a per-plugin basis and JIT MFA on a per-account basis are not affected. This issue has been patched in version 3.14.15.

Affected Software

1 affected component
Ovh The-bastion<3.14.15

Event History

Nov 8, 2023
CVE Published
03:26 PM
Data Sourced
03:26 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is CVE-2023-45140?

CVE-2023-45140 is a vulnerability in The Bastion software that allows for a bypass of group-based JIT (Just-in-Time) MFA (Multi-Factor Authentication) on SCP and SFTP connections.

2

What is the severity of CVE-2023-45140?

CVE-2023-45140 has a severity rating of medium with a CVSS score of 4.8.

3

How does CVE-2023-45140 affect The Bastion?

CVE-2023-45140 affects The Bastion version up to and excluding 3.14.15.

4

How can I fix CVE-2023-45140?

To fix CVE-2023-45140, update your installation of The Bastion to version 3.14.15 or higher.

5

Where can I find more information about CVE-2023-45140?

You can find more information about CVE-2023-45140 in the advisory and release notes provided by Ovh on their GitHub page.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203