0
0
Fork 0
mirror of https://github.com/discourse/discourse.git synced 2026-08-06 00:15:24 +08:00
discourse/app
Nat aea3519079 SECURITY: Prevent any signed AWS SNS TopicARN from being accepted via webhooks [backport 2026.5]
Backport of #732 to release/2026.5.

---

Any AWS account holder can subscribe their own SNS topic to a Discourse instance's /webhooks/aws and publish bounce notifications that AWS will sign legitimately. The forged bounces are processed against arbitrary user emails, bumping bounce_score and eventually triggering email revocation..

This fix adds a new `aws_sns_topic_arn_allowlist` site setting. Also hardens Jobs::ProcessSnsNotification against three issues:
- Binds bounces to (message_id, to_address) via find_by, so a legitimately-subscribed SNS publisher can no longer bounce arbitrary recipients we didn't send to.
- Skips duplicate notifications (next if email_log.bounced?) — AWS SNS delivers at-least-once.
- Uses update! instead of update_columns so EmailLog's existing before_save normalizes the bounce status code.

Also add a dashboard problem flags self-hosted admins whose SMTP looks like SES but who haven't set the allowlist yet.

https://github.com/discourse/discourse/security/advisories/GHSA-8f9m-v436-wr3x
2026-06-30 16:17:06 +02:00
..
assets UX: Redesign custom date range picker on new admin dashboard (#40355) 2026-05-28 14:14:30 +08:00
controllers SECURITY: Prevent any signed AWS SNS TopicARN from being accepted via webhooks [backport 2026.5] 2026-06-30 16:17:06 +02:00
helpers FIX: Apply embed class_name to <html> in full app mode (#40344) 2026-05-27 17:31:03 -03:00
jobs SECURITY: Prevent any signed AWS SNS TopicARN from being accepted via webhooks [backport 2026.5] 2026-06-30 16:17:06 +02:00
mailers DEV: Enable Style/RedundantParentheses rubocop rule (#40095) 2026-05-19 15:48:09 +02:00
models SECURITY: Prevent any signed AWS SNS TopicARN from being accepted via webhooks [backport 2026.5] 2026-06-30 16:17:06 +02:00
queries/reports FIX: Enforce can_see_ip checks across admin IP features (#40019) 2026-05-19 11:37:20 +08:00
serializers SECURITY: Hidden post revisions leak through adjacent visible diffs [backport 2026.5] 2026-06-30 16:17:06 +02:00
services SECURITY: Prevent any signed AWS SNS TopicARN from being accepted via webhooks [backport 2026.5] 2026-06-30 16:17:06 +02:00
views DEV: Drop media-minmax polyfill (#40335) 2026-05-27 20:26:21 +01:00