Even with authorized_keys
is filled with allowed pubkeys, If noscraper
is enabled, It will allow anyone to use bouncer even it's pubkey is not in authorized_keys
.
Impact
Patches
Available on version 3.0.10
Workarounds
Disable noscraper
if you have authorized_keys
being set in config
References
This line of code is the cause.
Even with
authorized_keys
is filled with allowed pubkeys, Ifnoscraper
is enabled, It will allow anyone to use bouncer even it's pubkey is not inauthorized_keys
.Impact
Patches
Available on version 3.0.10
Workarounds
Disable
noscraper
if you haveauthorized_keys
being set in configReferences
This line of code is the cause.