漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
The Bastion ttyrec files are not signed after encryption by the osh-encrypt-rsync script
Vulnerability Description
The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. Session-recording ttyrec files, may be handled by the provided osh-encrypt-rsync script that is a helper to rotate, encrypt, sign, copy, and optionally move them to a remote storage periodically, if configured to. When running, the script properly rotates and encrypts the files using the provided GPG key(s), but silently fails to sign them, even if asked to.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
缺少必要的密码学步骤
Vulnerability Title
The Bastion 安全漏洞
Vulnerability Description
The Bastion是OVHcloud开源的一个身份验证系统。 The Bastion存在安全漏洞,该漏洞源于脚本未能正确签名文件,可能导致数据完整性问题。
CVSS Information
N/A
Vulnerability Type
N/A