VDB
Sign up
CRITICAL9.1

GHSA-9jjc-grg5-67gj

SQL injection vulnerability in Meshery

Quick fix

GHSA-9jjc-grg5-67gj — github.com/layer5io/meshery: upgrade to the fixed version with the command below.

go get github.com/layer5io/meshery@v0.6.179

Details

A SQL injection vulnerability in Meshery before 0.6.179 allows a remote attacker to obtain sensitive information and execute arbitrary code via the order parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/layer5io/meshery
Introduced in: 0Fixed in: 0.6.179
Fixgo get github.com/layer5io/meshery@v0.6.179

References