Headline
GHSA-5cf7-cxrf-mq73: Bostr Improper Authorization vulnerability
Even with authorized_keys is filled with allowed pubkeys, If noscraper is enabled, It will allow anyone to use bqouncer even it’s pubkey is not in authorized_keys.
Impact
- Private bouncer
Patches
Available on version 3.0.10
Workarounds
Disable noscraper if you have authorized_keys being set in config
References
This line of code is the cause.
Bostr Improper Authorization vulnerability
Moderate severity GitHub Reviewed Published Aug 1, 2024 in Yonle/bostr • Updated Aug 2, 2024