Meshery SQL Injection Vulnerability Affects Kubernetes-Based Infrastructure and Applications
CVE-2024-29031

7.5HIGH

Key Information:

Vendor

Meshery

Status
Vendor
CVE Published:
21 March 2024

What is CVE-2024-29031?

Meshery, the open-source, cloud-native manager for Kubernetes applications, has a vulnerability in its earlier versions that exposes sensitive information through SQL injection. Attackers can exploit this weakness by manipulating the order parameter of the GetMeshSyncResources function. The vulnerability is addressed in version 0.7.17, which includes a patch to enhance security and mitigate potential unauthorized access to sensitive data. Users are advised to upgrade to the latest version to ensure their infrastructure remains secure.

Affected Version(s)

meshery < 0.7.17

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.