mirror of
https://github.com/discourse/discourse.git
synced 2026-08-06 04:02:30 +08:00
Any AWS account holder can subscribe their own SNS topic to a Discourse instance's /webhooks/aws and publish bounce notifications that AWS will sign legitimately. The forged bounces are processed against arbitrary user emails, bumping bounce_score and eventually triggering email revocation.. This fix adds a new `aws_sns_topic_arn_allowlist` site setting. Also hardens Jobs::ProcessSnsNotification against three issues: - Binds bounces to (message_id, to_address) via find_by, so a legitimately-subscribed SNS publisher can no longer bounce arbitrary recipients we didn't send to. - Skips duplicate notifications (next if email_log.bounced?) — AWS SNS delivers at-least-once. - Uses update! instead of update_columns so EmailLog's existing before_save normalizes the bounce status code. Also add a dashboard problem flags self-hosted admins whose SMTP looks like SES but who haven't set the allowlist yet. https://github.com/discourse/discourse/security/advisories/GHSA-8f9m-v436-wr3x
20 lines
459 B
Ruby
Vendored
20 lines
459 B
Ruby
Vendored
# frozen_string_literal: true
|
|
|
|
class ProblemCheck::MissingAwsSnsTopicArn < ProblemCheck
|
|
self.priority = "low"
|
|
|
|
SES_SMTP_PATTERN = /(email-smtp|amazonses).*amazonaws\.com\z/i
|
|
|
|
def call
|
|
return no_problem if SiteSetting.aws_sns_topic_arn_allowlist.present?
|
|
return no_problem unless smtp_looks_like_ses?
|
|
|
|
problem
|
|
end
|
|
|
|
private
|
|
|
|
def smtp_looks_like_ses?
|
|
ActionMailer::Base.smtp_settings[:address].to_s.match?(SES_SMTP_PATTERN)
|
|
end
|
|
end
|