VendorsLayer5mesheryall versions
Vulnerabilities

Layer5 Meshery

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2021-31856
A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the /experimental/patternfiles endpoint (order parameter in GetMesheryPatterns in models/meshery_pattern_persister.go).
Published 2021-04-28 · Modified
9.8EPSS 0.754
CVE-2023-46575
A SQL injection vulnerability exists in Meshery prior to version v0.6.179, enabling a remote attacker to retrieve sensitive information and execute arbitrary code through the “order” parameter
Published 2023-11-24 · Modified
9.8EPSS 0.013
CVE-2024-36535
Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
Published 2024-07-24 · Analyzed
9.8EPSS 0.005
CVE-2024-35181
GHSL-2024-013 Meshery SQL Injection vulnerability
Published 2024-05-27 · Analyzed
8.1EPSS 0.016
CVE-2024-35182
GHSL-2024-014 Meshery SQL Injection vulnerability
Published 2024-05-27 · Analyzed
8.1EPSS 0.016
CVE-2024-29031
Meshery SQL Injection vulnerability
Published 2024-03-21 · Analyzed
7.5EPSS 0.010