Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5cf7-cxrf-mq73

Опубликовано: 02 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 4.6

Описание

Bostr Improper Authorization vulnerability

Even with authorized_keys is filled with allowed pubkeys, If noscraper is enabled, It will allow anyone to use bouncer even it's pubkey is not in authorized_keys.

Impact

  • Private bouncer

Patches

Available on version 3.0.10

Workarounds

Disable noscraper if you have authorized_keys being set in config

References

This line of code is the cause.

Пакеты

Наименование

bostr

npm
Затронутые версииВерсия исправления

< 3.0.10

3.0.10

EPSS

Процентиль: 44%
0.00212
Низкий

5.1 Medium

CVSS4

4.6 Medium

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 4.6
nvd
больше 1 года назад

Bostr is an nostr relay aggregator proxy that acts like a regular nostr relay. bostr let everyone in even having authorized_keys being set when noscraper is set to true. This vulnerability is fixed in 3.0.10.

EPSS

Процентиль: 44%
0.00212
Низкий

5.1 Medium

CVSS4

4.6 Medium

CVSS3

Дефекты

CWE-285