blob: 02431e4f9dfa097a068978319362103d8dddc0a2 [file] [log] [blame]
id: GO-2024-3050
modules:
- module: github.com/layer5io/meshery
non_go_versions:
- fixed: 0.7.22
vulnerable_at: 0.7.18
summary: Meshery SQL Injection vulnerability in github.com/layer5io/meshery
cves:
- CVE-2024-35181
ghsas:
- GHSA-9f24-jrv4-f8g5
references:
- advisory: https://github.com/advisories/GHSA-9f24-jrv4-f8g5
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-35181
- advisory: https://securitylab.github.com/advisories/GHSL-2024-013_GHSL-2024-014_Meshery
- web: https://github.com/meshery/meshery/blob/b331f45c9083d7abf6b90105072b04cd22473de7/server/handlers/meshsync_handler.go#L187
- web: https://github.com/meshery/meshery/commit/8e995ce21af02d32ef61689c1e1748a745917f13
- web: https://github.com/meshery/meshery/commit/b55f6064d0c6a965aee38f30281f99da7dc4420c
- web: https://github.com/meshery/meshery/pull/10207
- web: https://github.com/meshery/meshery/pull/10280
source:
id: GHSA-9f24-jrv4-f8g5
created: 2024-08-06T18:28:30.247664-04:00
review_status: UNREVIEWED