Meshery SQL Injection Vulnerability Affects Kubernetes-Based Infrastructure and Applications
CVE-2024-29031
7.5HIGH
What is CVE-2024-29031?
Meshery, the open-source, cloud-native manager for Kubernetes applications, has a vulnerability in its earlier versions that exposes sensitive information through SQL injection. Attackers can exploit this weakness by manipulating the order parameter of the GetMeshSyncResources function. The vulnerability is addressed in version 0.7.17, which includes a patch to enhance security and mitigate potential unauthorized access to sensitive data. Users are advised to upgrade to the latest version to ensure their infrastructure remains secure.
Affected Version(s)
meshery < 0.7.17
