CVE-2024-29031 Information

Description

Meshery is an open source cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery prior to version 0.7.17 allows a remote attacker to obtain sensitive information via the order parameter of GetMeshSyncResources. Version 0.7.17 contains a patch for this issue.

Reference

https://securitylab.github.com/advisories/GHSL-2023-249_Meshery/ https://github.com/meshery/meshery/pull/10207 https://github.com/meshery/meshery/commit/8e995ce21af02d32ef61689c1e1748a745917f13

Share on: