CVE-2023-45140: Group-based JIT MFA bypass on scp and sftp in The Bastion
The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. SCP and SFTP plugins don't honor group-based JIT MFA. Establishing a SCP/SFTP connection through The Bastion via a group access where MFA is enforced does not ask for additional factor. This abnormal behavior only applies to per-group-based JIT MFA. Other MFA setup types, such as Immediate MFA, JIT MFA on a per-plugin basis and JIT MFA on a per-account basis are not affected. This issue has been patched in version 3.14.15.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-45140?
CVE-2023-45140 is a vulnerability in The Bastion software that allows for a bypass of group-based JIT (Just-in-Time) MFA (Multi-Factor Authentication) on SCP and SFTP connections.
What is the severity of CVE-2023-45140?
CVE-2023-45140 has a severity rating of medium with a CVSS score of 4.8.
How does CVE-2023-45140 affect The Bastion?
CVE-2023-45140 affects The Bastion version up to and excluding 3.14.15.
How can I fix CVE-2023-45140?
To fix CVE-2023-45140, update your installation of The Bastion to version 3.14.15 or higher.
Where can I find more information about CVE-2023-45140?
You can find more information about CVE-2023-45140 in the advisory and release notes provided by Ovh on their GitHub page.