Bostr Improper Authorization vulnerability
Description
Published by the National Vulnerability Database
Aug 1, 2024
Published to the GitHub Advisory Database
Aug 2, 2024
Reviewed
Aug 2, 2024
Last updated
Aug 2, 2024
Even with
authorized_keysis filled with allowed pubkeys, Ifnoscraperis enabled, It will allow anyone to use bouncer even it's pubkey is not inauthorized_keys.Impact
Patches
Available on version 3.0.10
Workarounds
Disable
noscraperif you haveauthorized_keysbeing set in configReferences
This line of code is the cause.
References