GHSL-2023-136: Remote Code Execution (RCE) in Samson
Published Aug 14, 2024
·Updated
Samson’s Kubernetes::RoleVerificationsController deserializes user-controllable data leading to Remote Code Execution (RCE).
Affected Software
1 affected component
Zendesk Samson
Event History
Aug 14, 2024
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of GHSL-2023-136?
The severity of GHSL-2023-136 is rated at 89, indicating a high risk level.
2
How do I fix GHSL-2023-136?
To mitigate GHSL-2023-136, upgrade Zendesk Samson to the latest version that addresses this vulnerability.
3
What does GHSL-2023-136 affect?
GHSL-2023-136 affects the Zendesk Samson application, specifically its Kubernetes::RoleVerificationsController component.
4
What is the impact of exploiting GHSL-2023-136?
Exploiting GHSL-2023-136 allows attackers to achieve Remote Code Execution (RCE) on vulnerable systems.
5
When was GHSL-2023-136 published?
GHSL-2023-136 was published on August 14, 2024.