PT-2025-38246 · Unknown+1 · The Bastion+2
Siv0
·
Published
2025-09-17
·
Updated
2025-09-18
·
CVE-2025-59339
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
The Bastion (affected versions not specified)
Description
The Bastion provides authentication, authorization, traceability, and auditability for SSH accesses. Session-recording ttyrec files are handled by the provided
osh-encrypt-rsync script, which is used to rotate, encrypt, sign, copy, and optionally move them to remote storage. The script rotates and encrypts the files using the provided GPG key(s) but silently fails to sign them, even when signing is requested.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gpg
The Bastion
Osh-Encrypt-Rsync