The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. Session-recording ttyrec files, may be handled by the provided osh-encrypt-rsync script that is a helper to rotate, encrypt, sign, copy, and optionally move them to a remote storage periodically, if configured to. When running, the script properly rotates and encrypts the files using the provided GPG key(s), but silently fails to sign them, even if asked to.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Sep 2025 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ovh
Ovh the-bastion |
|
Vendors & Products |
Ovh
Ovh the-bastion |
Wed, 17 Sep 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 17 Sep 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. Session-recording ttyrec files, may be handled by the provided osh-encrypt-rsync script that is a helper to rotate, encrypt, sign, copy, and optionally move them to a remote storage periodically, if configured to. When running, the script properly rotates and encrypts the files using the provided GPG key(s), but silently fails to sign them, even if asked to. | |
Title | The Bastion ttyrec files are not signed after encryption by the osh-encrypt-rsync script | |
Weaknesses | CWE-325 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-09-17T17:50:34.877Z
Updated: 2025-09-17T18:09:55.732Z
Reserved: 2025-09-12T12:36:24.635Z
Link: CVE-2025-59339

Updated: 2025-09-17T18:08:39.833Z

Status : Awaiting Analysis
Published: 2025-09-17T18:15:53.230
Modified: 2025-09-18T13:43:34.310
Link: CVE-2025-59339

No data.