Headline
GHSA-5cf7-cxrf-mq73: Bostr Improper Authorization vulnerability
Even with authorized_keys
is filled with allowed pubkeys, If noscraper
is enabled, It will allow anyone to use bqouncer even it’s pubkey is not in authorized_keys
.
Impact
- Private bouncer
Patches
Available on version 3.0.10
Workarounds
Disable noscraper
if you have authorized_keys
being set in config
References
This line of code is the cause.
Bostr Improper Authorization vulnerability
Moderate severity GitHub Reviewed Published Aug 1, 2024 in Yonle/bostr • Updated Aug 2, 2024