PT-2025-38246 · Unknown+1 · The Bastion+2

Siv0

·

Published

2025-09-17

·

Updated

2025-09-18

·

CVE-2025-59339

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions The Bastion (affected versions not specified)
Description The Bastion provides authentication, authorization, traceability, and auditability for SSH accesses. Session-recording ttyrec files are handled by the provided osh-encrypt-rsync script, which is used to rotate, encrypt, sign, copy, and optionally move them to remote storage. The script rotates and encrypts the files using the provided GPG key(s) but silently fails to sign them, even when signing is requested.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2025-59339
GHSA-H66Q-G57P-RGG6

Affected Products

Gpg
The Bastion
Osh-Encrypt-Rsync