{"id":"CVE-2024-29031","summary":"Meshery SQL Injection vulnerability","details":"Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery prior to version 0.7.17 allows a remote attacker to obtain sensitive information via the `order` parameter of `GetMeshSyncResources`. Version 0.7.17 contains a patch for this issue.","aliases":["GHSA-652r-q29p-m25h","GO-2024-3045"],"modified":"2026-08-12T03:51:26.577898526Z","published":"2024-03-21T22:16:03.997Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/29xxx/CVE-2024-29031.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/29xxx/CVE-2024-29031.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-29031"},{"type":"ADVISORY","url":"https://securitylab.github.com/advisories/GHSL-2023-249_Meshery/"},{"type":"FIX","url":"https://github.com/meshery/meshery/commit/8e995ce21af02d32ef61689c1e1748a745917f13"},{"type":"FIX","url":"https://github.com/meshery/meshery/pull/10207"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/meshery/meshery","events":[{"introduced":"0"},{"fixed":"5c7409cc17eb0913073243e0fca2b16c5b9b7f37"},{"fixed":"8e995ce21af02d32ef61689c1e1748a745917f13"}],"database_specific":{"cpe":"cpe:2.3:a:layer5:meshery:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.7.17"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v0.7.16","v0.7.15","v0.7.14","v0.7.13","v0.7.12","v0.7.11-patch.3","v0.7.11-patch.2","v0.7.11","v0.7.11-patch.1","v0.7.10","v0.7.9","v0.7.8.patch-1","v0.7.8","v0.7.7","v0.7.6","v0.7.5","v0.7.4-patch.1","v0.7.4","v0.7.3-patch.4","v0.7.3-patch.2","v0.7.3-patch.3","v0.7.3","v0.7.2","v0.7.2-rc-2","v0.7.2-rc-1","v0.7.1","v0.7.0","v0.7.0-beta-4","v0.7.0-beta-3","v0.7.0-beta-2","v0.7.0-beta-1","v0.6.183","v0.6.184","v0.6.182","v0.6.181","v0.6.180","v0.6.179","v0.6.178","v0.6.177","v0.6.176","v0.6.175","v0.6.174","v0.6.173","v0.6.172","v0.6.171","v0.6.169","v0.6.168","v0.6.167","v0.6.166","v0.6.165","v0.6.162","v0.6.161","v0.6.160","v0.6.159","v0.6.158","v0.6.157","v0.6.156","v0.6.155","v0.6.154","v0.6.153","v0.6.152","v0.6.151","v0.6.150","v0.6.149","v0.6.148","v0.6.147","v0.6.146","v0.6.144","v0.6.142","v0.6.141","v0.6.140","v0.6.139","v0.6.138","v0.6.137","v0.6.136","v0.6.135","v0.6.134","v0.6.133","v0.6.132","v0.6.131","v0.6.129","v0.6.108","v0.6.107","v0.6.106","v0.6.105","v0.6.104","v0.6.103","v0.6.100","v0.6.98","v0.6.97","v0.6.96","v0.6.95","v0.6.94","v0.6.93","v0.6.92","v0.6.91","v0.6.90","v0.6.89","v0.6.88","v0.6.87","v0.6.86","v0.6.85","v0.6.84","v0.6.83","v0.6.82","v0.6.81","v0.6.80","v0.6.79","v0.6.78","v0.6.77","v0.6.76","v0.6.73","v0.6.75","v0.6.74","v0.6.72","v0.6.71","v0.6.70","v0.6.69","v0.6.68","v0.6.67","v0.6.66","v0.6.65","v0.6.64","v0.6.63","v0.6.62","v0.6.61","v0.6.60","v0.6.59","v0.6.58","v0.6.57","v0.6.56","v0.6.55","v0.6.54","v0.6.53","v0.6.52","v0.6.51","v0.6.50","v0.6.49","v0.6.48","v0.6.47","v0.6.10","v0.6.9","v0.6.8","v0.6.7","v0.6.6","v0.6.5","v0.6.4","v0.6.3","v0.6.2","v0.6.0-rc.6ff","v0.6.0-rc.6fe","v0.6.0-rc.6fd","v0.6.0-rc.6fc","v0.6.0-rc.6fb","v0.6.0-rc.6fa","v0.6.0-rc.6f","v0.6.0-rc.6e","v0.6.0-rc.6d","v0.6.0-rc.6c","v0.6.0-rc.6b","v0.6.0-rc.6a","v0.6.0-rc.6","v0.6.0-rc.5aa","v0.6.0-rc.5z","v0.6.0-rc.5y","v0.6.0-rc.5x","v0.6.0-rc.5w","v0.6.0-rc.5v","v0.6.0-rc.5u","v0.6.0-rc-5t","v0.6.0-rc.5s","v0.6.0-rc.5r","v0.6.0-rc.5q","v0.6.0-rc.5p","v0.6.0-rc.5o","v0.6.0-rc.5n","v0.6.0-rc.5m","v0.6.0-rc.5l","v0.6.0-rc.5k","v0.6.0-rc-5j","v0.6.0-rc-5h","v0.6.0-rc-5g","v0.6.0-rc-5f","v0.6.0-rc-5d","v0.6.0-rc-5c","v0.6.0-rc-5a","v0.6.0-rc-5","v0.6.0-rc-4","v0.6.0-rc-3","v0.6.0-rc-2","v0.6.0-rc-1","v0.5.72","v0.5.71","v0.5.70","v0.5.69","v0.5.68","v0.5.67","v0.5.66","v0.5.64","v0.5.65","v0.5.64-rc-2","v0.5.63-rc-1","v0.5.62","v0.5.61","v0.5.60","v0.5.59","v0.5.58","v0.5.57","v0.5.56","v0.5.55","v0.5.54","v0.5.53","v0.5.52","v0.5.51","v0.5.50","v0.5.49","v0.5.48","v0.5.47","v0.5.46","v0.5.45","v0.5.44","v0.5.43","v0.5.42","v0.5.39","v0.5.38","v0.5.37","v0.5.36","v0.5.34","v0.5.35","v0.5.33","v0.5.32","v0.5.31","v0.5.30","v0.5.29","v0.5.28","v0.5.27","v0.5.26","v0.5.25","v0.5.24","v0.5.23","v0.5.22","v0.5.21","v0.5.20","v0.5.19","v0.5.18","v0.5.17","v0.5.16","v0.5.15","v0.5.14","v0.5.13","v0.5.11","v0.5.10","v0.5.9","v0.5.8","v0.5.7","v0.5.6","v0.5.5","v0.5.4","v0.5.3","v0.5.2","v0.5.1","v0.5.0","v0.5.0-rc-6","v0.5.0-rc-5","v0.5.0-rc-4","v0.5.0-beta-4","v0.5.0-beta-3","v0.5.0-beta-2","v0.5.0-beta-1","v0.4.27","v0.4.26","v0.4.25","v0.4.24","v0.4.23","v0.4.15","v0.4.21","v0.4.22","v0.4.20","v0.4.18","v0.4.19","v0.4.14","v0.4.17","v0.4.13","v0.4.12","v0.4.11","v0.4.10","v0.4.9","v0.4.8","v0.4.7","v0.4.2","v0.4.6","v0.4.5","v0.4.4","v0.4.3","v0.4.1","v0.4.0","v0.4.0-rc.0","v0.4.0-beta.4","v0.4.0-beta.3","v0.4.0-beta.2","v0.3.19","v0.4.0-beta.1","v0.3.18","v0.3.17","v0.3.16","v0.3.15","v0.3.14","v0.3.13","v0.3.12","v0.3.11","v0.3.10","v0.3.9","v0.3.8","v0.3.7","v0.3.6","v0.3.5","v0.3.4","v0.3.3","v0.3.2","v0.3.1","v0.2.4","v0.2.3","v0.2.2","v0.2.1","v0.2.0","v0.1.6","v0.1.5","v0.1.4","v0.0.6","v0.1.3","v0.1.2","v0.0.7","v0.3.0","v0.0.3","v0.0.2","v0.1.0","v0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-29031.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}