QID 730264
Date Published: 2021-11-18
QID 730264: Discourse Remote Code Execution (RCE) via malicious Simple Notification Service (SNS) subscription payload
Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution.
This resulted from a lack of validation in subscribe_url values. This issue is patched in the latest stable, beta and tests-passed versions of Discourse.
Affected versions:
stable <= 2.7.8; beta <= 2.8.0.beta6; tests-passed <= 2.8.0.beta6
QID Detection Logic: (Remote)
It checks Discourse package versions to check for the vulnerable packages.
This QID checks for the following: It request to the main page in the host (index) and looks for the version information.
Successful exploitation allows an unauthenticated, remote attacker to execute arbitrary code on the targeted system.
Customers are advised to visit RCE via malicious SNS subscription payload webpage for release notes.
Workaround:
To workaround the issue without updating, requests with a path starting /webhooks/aws path could be blocked at an upstream proxy.
- RCE via malicious SNS subscription payload -
github.com/discourse/discourse/security/advisories/GHSA-jcjx-pvpc-qgwq
CVEs related to QID 730264
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Discourse |
|