Executive brief
Bostr is a bouncer service that acts as a proxy for Nostr relays (a decentralized social network protocol). When administrators configure Bostr with a whitelist of authorized cryptographic keys, the system should only allow those approved keys to access the service. However, when a feature called "noscraper" is enabled, a logic error in the authentication code bypasses this whitelist entirely, allowing unauthorized users to gain access. For private relay deployments relying on key-based access control, this means attackers can intercept, modify, or access sensitive relay data.
Technical details
The vulnerability is a logic error in the auth.js authentication module (CWE-285: Improper Authorization). The vulnerable code used a flawed boolean expression (`!authorized_keys?.includes(data.pubkey) && !private_keys[data.pubkey] && !noscraper`) that failed to properly enforce the key whitelist when noscraper was enabled. The attack is unauthenticated at the network level (any remote client can attempt it), but requires the noscraper feature to be enabled in the configuration and the bouncer to be network-accessible. An attacker can bypass authentication and gain full access to the bouncer, potentially reading, modifying, or censoring relay events. The fix, released in version 3.0.10, corrects the logic to properly validate public keys against the authorized_keys and private_keys configuration regardless of the noscraper setting.
Affected products
- Yonle bostr <3.0.10
Timeline
- 2024-08-01: disclosed: Advisory published on GitHub
- 2024-08-01: patched: Fix released in version 3.0.10
References
- https://github.com/Yonle/bostr/security/advisories/GHSA-5cf7-cxrf-mq73
- https://github.com/Yonle/bostr/commit/49181f4ec9ae1472c6675cab56bbc01e723855af
- https://github.com/Yonle/bostr
- https://github.com/Yonle/bostr/blob/8665374a66e2afb9f92d0414b0d6f420a95d5d2d/auth.js
- https://github.com/Yonle/bostr/releases/tag/3.0.10