Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-652r-q29p-m25h

Опубликовано: 05 авг. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Meshery SQL Injection vulnerability

Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery prior to version 0.7.17 allows a remote attacker to obtain sensitive information via the order parameter of GetMeshSyncResources. Version 0.7.17 contains a patch for this issue.

Пакеты

Наименование

github.com/layer5io/meshery

go
Затронутые версииВерсия исправления

< 0.7.17

0.7.17

EPSS

Процентиль: 78%
0.0119
Низкий

7.5 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.5
nvd
почти 2 года назад

Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery prior to version 0.7.17 allows a remote attacker to obtain sensitive information via the `order` parameter of `GetMeshSyncResources`. Version 0.7.17 contains a patch for this issue.

EPSS

Процентиль: 78%
0.0119
Низкий

7.5 High

CVSS3

Дефекты

CWE-89