{"id":"CVE-2023-45140","summary":"Group-based JIT MFA bypass on scp and sftp in The Bastion","details":"The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. SCP and SFTP plugins don't honor group-based JIT MFA. Establishing a SCP/SFTP connection through The Bastion via a group access where MFA is enforced does not ask for additional factor. This abnormal behavior only applies to per-group-based JIT MFA. Other MFA setup types, such as Immediate MFA, JIT MFA on a per-plugin basis and JIT MFA on a per-account basis are not affected. This issue has been patched in version 3.14.15.","aliases":["GHSA-pr4q-w883-pf5x"],"modified":"2026-08-12T03:51:47.442852349Z","published":"2023-11-08T15:26:26.584Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/45xxx/CVE-2023-45140.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-306"]},"references":[{"type":"WEB","url":"https://github.com/ovh/the-bastion/releases/tag/v3.14.15"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/45xxx/CVE-2023-45140.json"},{"type":"ADVISORY","url":"https://github.com/ovh/the-bastion/security/advisories/GHSA-pr4q-w883-pf5x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-45140"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ovh/the-bastion","events":[{"introduced":"0"},{"fixed":"137c7b54540595f557debe3c804f00553119bd60"}],"database_specific":{"extracted_events":[{"introduced":"3.0.0"},{"last_affected":"3.14.0"},{"introduced":"0"},{"fixed":"3.14.15"}],"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:ovh:the-bastion:*:*:*:*:*:*:*:*"}}],"versions":["v3.14.00","v3.13.01","v3.13.00","v3.12.00","v3.11.02","v3.11.01","v3.11.00","v3.10.00","v3.09.02","v3.09.00-really","v3.09.00","v3.09.00-rc3","v3.09.00-rc2","v3.09.00-rc1","v3.08.01","v3.08.00","v3.07.00","v3.06.00","v3.05.01","v3.05.00","v3.04.00","v3.03.99-rc2","v3.03.99-rc1","v3.03.01","v3.03.00","v3.02.00","v3.01.99-rc4","v3.01.99-rc3","v3.01.99-rc2","v3.01.99-rc1","v3.01.03","v3.01.02","v3.01.01","v3.01.00","v3.00.02","v3.00.01","v3.00.00"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-45140.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"}]}