The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. SCP and SFTP plugins don't honor group-based JIT MFA. Establishing a SCP/SFTP connection through The Bastion via a group access where MFA is enforced does not ask for additional factor. This abnormal behavior only applies to per-group-based JIT MFA. Other MFA setup types, such as Immediate MFA, JIT MFA on a per-plugin basis and JIT MFA on a per-account basis are not affected. This issue has been patched in version 3.14.15.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-09-12T19:10:42.145Z

Reserved: 2023-10-04T16:02:46.329Z

Link: CVE-2023-45140

cve-icon Vulnrichment

Updated: 2024-08-02T20:14:19.158Z

cve-icon NVD

Status : Modified

Published: 2023-11-08T16:15:09.800

Modified: 2024-11-21T08:26:25.670

Link: CVE-2023-45140

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.