Impact
A flaw in Bastillion’s Public Key Management System, specifically in the AuthKeysKtrl.java component, allows an attacker to execute arbitrary operating‑system commands. The vulnerability arises from unsafe handling of user input that is passed to a system shell, leading to command injection. If successfully exploited, the attacker could compromise Bastillion’s confidentiality, integrity, and availability by running any command on the underlying host.
Affected Systems
Bastillion version 4.0.1 and all earlier releases are affected. The weakness resides in the AuthKeysKtrl module of the key‑management subsystem, and no other versions or products are listed as impacted.
Risk and Exploitability
The base CVSS score of 5.1 places this issue in the medium severity range, while the EPSS score of 4% suggests a low but non‑negligible likelihood of exploitation at present. The vulnerability is not catalogued in CISA KEV and an exploit has been publicly disclosed, potentially usable. It is inferred that attackers can trigger the injection remotely via the exposed management interface, and the description does not mention a requirement for local privileges or authenticated sessions; thus, restricting network accessibility to trusted administrators is recommended.
OpenCVE Enrichment