Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery prior to version 0.7.17 allows a remote attacker to obtain sensitive information via the `order` parameter of `GetMeshSyncResources`. Version 0.7.17 contains a patch for this issue.
References
Configurations
No configuration.
History
21 Nov 2024, 09:07
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://github.com/meshery/meshery/commit/8e995ce21af02d32ef61689c1e1748a745917f13 - | |
References | () https://github.com/meshery/meshery/pull/10207 - | |
References | () https://securitylab.github.com/advisories/GHSL-2023-249_Meshery/ - |
21 Mar 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-21 23:15
Updated : 2024-11-21 09:07
NVD link : CVE-2024-29031
Mitre link : CVE-2024-29031
CVE.ORG link : CVE-2024-29031
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')