CVE-2024-29031: LAYER5 Meshery

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery prior to version 0.7.17 allows a remote attacker to obtain sensitive information via the `order` parameter of `GetMeshSyncResources`. Version 0.7.17 contains a patch for this issue.

Affected products

  • LAYER5 Meshery: before 0.7.17 (fixed in 0.7.17)

Published 2024-03-21. Last modified 2026-06-17.