Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Bastion/
  3. Bastion

Bastion

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 34 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Multi-framework compliance & security platform for scale-up companies.

by Bastion · bastion.tech · source ↗

Known CVEs (34)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-44347 ↗MEDIUM 5.82026

    Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.23.3, the SSO flow does not validate the state parameter, which makes it possible for an attacker to trick a user int…

  • CVE-2026-31864 ↗MEDIUM 6.82026

    JumpServer is an open source bastion host and an operation and maintenance security audit system. a Server-Side Template Injection (SSTI) vulnerability exists in JumpServer's Applet and VirtualApp upl…

  • CVE-2026-31798 ↗MEDIUM 5.02026

    JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v4.10.16-lts, JumpServer improperly validates certificates in the Custom SMS API Client. When…

  • CVE-2025-58044 ↗MEDIUM 6.12025

    JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// endpoint uses the Referer header as the redirection ta…

  • CVE-2025-49752 ↗CRITICAL 10.02025

    Azure Bastion Elevation of Privilege Vulnerability

  • CVE-2023-7325 ↗2025

    Anheng Mingyu Operation and Maintenance Audit and Risk Control System up to 2023-08-10 contains a server-side request forgery (SSRF) vulnerability in the xmlrpc.sock handler. The product accepts speci…

  • CVE-2025-62795 ↗HIGH 7.12025

    JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts and v4.10.12-lts, a low-privileged authenticated user can invoke LDAP configurat…

  • CVE-2025-62712 ↗CRITICAL 9.62025

    JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions prior to v3.10.20-lts and v4.10.11-lts, an authenticated, non-privileged user c…

  • CVE-2025-59339 ↗MEDIUM 4.42025

    The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. Session-recording ttyrec files, may be handled by the provided osh-encrypt-rsync script that is a he…

  • CVE-2025-27095 ↗MEDIUM 4.32025

    JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.8.0 and 3.10.18, an attacker with a low-privileged account can access the Kubernetes sessio…

  • CVE-2024-29202 ↗CRITICAL 9.92024

    JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection vulnerability in JumpServer's Ansible to execute arb…

  • CVE-2024-29201 ↗CRITICAL 9.92024

    JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism in JumpServer's Ansible to execute arbitrary code …

  • CVE-2024-29024 ↗MEDIUM 4.62024

    JumpServer is an open source bastion host and an operation and maintenance security audit system. An authenticated user can exploit the Insecure Direct Object Reference (IDOR) vulnerability in the fil…

  • CVE-2024-29020 ↗MEDIUM 4.62024

    JumpServer is an open source bastion host and an operation and maintenance security audit system. An authorized attacker can obtain sensitive information contained within playbook files if they manage…

  • CVE-2024-24763 ↗MEDIUM 4.32024

    JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10.0, attackers can exploit this vulnerability to construct malicious links, leadin…

  • CVE-2023-49961 ↗HIGH 7.52024

    WALLIX Bastion 7.x, 8.x, 9.x and 10.x and WALLIX Access Manager 3.x and 4.x have Incorrect Access Control which can lead to sensitive data exposure.

  • CVE-2023-48712 ↗HIGH 7.12023

    Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. In affected versions there is a privilege escalation vulnerability through a non-admin user's account. Limited users can imperso…

  • CVE-2023-45140 ↗MEDIUM 4.82023

    The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. SCP and SFTP plugins don't honor group-based JIT MFA. Establishing a SCP/SFTP connection through The…

  • CVE-2023-40453 ↗MEDIUM 6.52023

    Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, which might potentially trick an administrator into performing an unsafe action (vi…

  • CVE-2023-46138 ↗LOW 3.72023

    JumpServer is an open source bastion host and maintenance security audit system that complies with 4A specifications. Prior to version 3.8.0, the default email for initial user admin is `admin[@]mycom…

  • …and 14 more

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other GRC & Compliance Automation products

see all →
  • 3rdRisk Platform · 3rdRisk Solutions B.V.
  • 3rdcomply · 3rdcomply
  • 6clicks GRC · 6clicks
  • A-LIGN A-SCEND · A-LIGN
  • ANOZR WAY AY PeopleSight · ANOZR WAY
  • ARCON Security Compliance Management · ARCON
  • ASPIA Audit Management · ASPIA Infotech Pvt. Ltd.
  • ASPIA KRI Module · ASPIA Infotech Pvt. Ltd.