Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2508 | Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery prior to version 0.7.17 allows a remote attacker to obtain sensitive information via the `order` parameter of `GetMeshSyncResources`. Version 0.7.17 contains a patch for this issue. |
Github GHSA |
GHSA-652r-q29p-m25h | Meshery SQL Injection vulnerability |
Tue, 02 Sep 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Layer5
Layer5 meshery |
|
| CPEs | cpe:2.3:a:layer5:meshery:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Layer5
Layer5 meshery |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-13T16:48:48.015Z
Reserved: 2024-03-14T16:59:47.612Z
Link: CVE-2024-29031
Updated: 2024-08-02T01:03:51.701Z
Status : Analyzed
Published: 2024-03-21T23:15:11.167
Modified: 2025-09-02T19:25:57.483
Link: CVE-2024-29031
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA