PT-2024-22684 · Meshery · Meshery

Tony Torralba

·

Published

2024-03-21

·

Updated

2025-09-02

·

CVE-2024-29031

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Meshery versions prior to 0.7.17
Description A SQL injection issue allows a remote attacker to obtain sensitive information via the order parameter of GetMeshSyncResources. This affects Meshery's ability to manage Kubernetes-based infrastructure and applications securely.
Recommendations For versions prior to 0.7.17, update to version 0.7.17 to resolve the issue. As a temporary workaround, consider restricting access to the GetMeshSyncResources function or avoiding the use of the order parameter until the update is applied.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-29031
GHSA-652R-Q29P-M25H
GO-2024-3045

Affected Products

Meshery