BastionGuard Security Center
Security advisories, coordinated vulnerability disclosure, official CVE records, supported releases, and acknowledgments for responsible security research.
Report a vulnerability
Send a confidential security report directly to the BastionGuard Security Team.
Report securelyDisclosure policy
Review our scope, response targets, safe-harbor principles, and coordinated-disclosure process.
Read the policySecurity advisories
Review affected components, severity, versions, fixes, public references, and researcher credits.
View advisoriesBastionGuard CVEs
View official CVE records synchronized from the CVE Program CVE List.
View CVE recordsAcknowledgments
Recognize researchers who helped improve BastionGuard through responsible disclosure.
View acknowledgmentsSecurity contact
Contact the team using the published security address and standardized security.txt endpoint.
Send emailSupported BastionGuard releases
Security fixes are provided for supported releases. Users should upgrade promptly when a security update is published.
| Version | Status | Guidance |
|---|---|---|
| 2.0.2 | Supported | Current stable release |
| 2.0.1 | Unsupported | Security update required |
| 2.0 | Unsupported | Security update required |
Recent security advisories
Local Privilege Escalation via OS Command Injection in bastionguard-firewall
A local privilege-escalation vulnerability in the setuid-root bastionguard-firewall helper affects BastionGuard 2.0 and 2.0.1.
- Component
- bastionguard-firewall
- Affected
- 2.0, 2.0.1
- Fixed
- 2.0.2