{"id":"CVE-2024-41962","aliases":["GHSA-5cf7-cxrf-mq73"],"url":"https://o3.security/vulnerability/CVE-2024-41962","summary":"Bostr Improper Authorization","details":"Even with `authorized_keys` is filled with allowed pubkeys, If `noscraper` is enabled, It will allow anyone to use bouncer even it's pubkey is not in `authorized_keys`.\n\n### Impact\n- Private bouncer\n\n### Patches\nAvailable on version [3.0.10](https://github.com/Yonle/bostr/releases/tag/3.0.10)\n\n### Workarounds\nDisable `noscraper` if you have `authorized_keys` being set in config\n\n### References\nThis [line of code](https://github.com/Yonle/bostr/blob/8665374a66e2afb9f92d0414b0d6f420a95d5d2d/auth.js#L21) is the cause.","published":"2024-08-01T16:30:57.629Z","modified":"2026-08-12T03:51:28.464491485Z","cvss":{"score":4.6,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"bostr","fixedVersion":"3.0.10"}],"fix":{"url":"https://github.com/Yonle/bostr/commit/49181f4ec9ae1472c6675cab56bbc01e723855af","label":"Yonle/bostr@49181f4"},"references":[{"type":"WEB","url":"https://github.com/Yonle/bostr/blob/8665374a66e2afb9f92d0414b0d6f420a95d5d2d/auth.js#L21"},{"type":"WEB","url":"https://github.com/Yonle/bostr/releases/tag/3.0.10"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/41xxx/CVE-2024-41962.json"},{"type":"ADVISORY","url":"https://github.com/Yonle/bostr/security/advisories/GHSA-5cf7-cxrf-mq73"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-41962"},{"type":"FIX","url":"https://github.com/Yonle/bostr/commit/49181f4ec9ae1472c6675cab56bbc01e723855af"},{"type":"PACKAGE","url":"https://github.com/Yonle/bostr"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:28.464491485Z"}}