CVE-2023-46575
Dashboard / Vulnerabilities / CVE-2023-46575
Summary:
Details: A SQL injection vulnerability exists in Meshery prior to version v0.6.179, enabling a remote attacker to retrieve sensitive information and execute arbitrary code through the “order” parameter
References: https://github.com/meshery/meshery/compare/v0.6.178...v0.6.179, https://meshery.io, https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/46xxx/CVE-2023-46575.json, https://nvd.nist.gov/vuln/detail/CVE-2023-46575, https://github.com/meshery/meshery/commit/ffe00967acfe4444a5db08ff3a4cafb9adf6013f, https://github.com/meshery/meshery/pull/9372
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
v0.6.178
v0.6.177
v0.6.176
v0.6.175
v0.6.174
v0.6.173
v0.6.172
v0.6.171
v0.6.169
v0.6.168
v0.6.167
v0.6.166
v0.6.165
v0.6.162
v0.6.161
v0.6.160
v0.6.159
v0.6.158
v0.6.157
v0.6.156
v0.6.155
v0.6.154
v0.6.153
v0.6.152
v0.6.151
v0.6.150
v0.6.149
v0.6.148
v0.6.147
v0.6.146
v0.6.144
v0.6.142
v0.6.141
v0.6.140
v0.6.139
v0.6.138
v0.6.137
v0.6.136
v0.6.135
v0.6.134
v0.6.133
v0.6.132
v0.6.131
v0.6.129
v0.6.108
v0.6.107
v0.6.106
v0.6.105
v0.6.104
v0.6.103
v0.6.100
v0.6.98
v0.6.97
v0.6.96
v0.6.95
v0.6.94
v0.6.93
v0.6.92
v0.6.91
v0.6.90
v0.6.89
v0.6.88
v0.6.87
v0.6.86
v0.6.85
v0.6.84
v0.6.83
v0.6.82
v0.6.81
v0.6.80
v0.6.79
v0.6.78
v0.6.77
v0.6.76
v0.6.73
v0.6.75
v0.6.74
v0.6.72
v0.6.71
v0.6.70
v0.6.69
v0.6.68
v0.6.67
v0.6.66
v0.6.65
v0.6.64
v0.6.63
v0.6.62
v0.6.61
v0.6.60
v0.6.59
v0.6.58
v0.6.57
v0.6.56
v0.6.55
v0.6.54
v0.6.53
v0.6.52
v0.6.51
v0.6.50
v0.6.49
v0.6.48
v0.6.47
v0.6.10
v0.6.9
v0.6.8
v0.6.7
v0.6.6
v0.6.5
v0.6.4
v0.6.3
v0.6.2
v0.6.0-rc.6ff
v0.6.0-rc.6fe
v0.6.0-rc.6fd
v0.6.0-rc.6fc
v0.6.0-rc.6fb
v0.6.0-rc.6fa
v0.6.0-rc.6f
v0.6.0-rc.6e
v0.6.0-rc.6d
v0.6.0-rc.6c
v0.6.0-rc.6b
v0.6.0-rc.6a
v0.6.0-rc.6
v0.6.0-rc.5aa
v0.6.0-rc.5z
v0.6.0-rc.5y
v0.6.0-rc.5x
v0.6.0-rc.5w
v0.6.0-rc.5v
v0.6.0-rc.5u
v0.6.0-rc-5t
v0.6.0-rc.5s
v0.6.0-rc.5r
v0.6.0-rc.5q
v0.6.0-rc.5p
v0.6.0-rc.5o
v0.6.0-rc.5n
v0.6.0-rc.5m
v0.6.0-rc.5l
v0.6.0-rc.5k
v0.6.0-rc-5j
v0.6.0-rc-5h
v0.6.0-rc-5g
v0.6.0-rc-5f
v0.6.0-rc-5d
v0.6.0-rc-5c
v0.6.0-rc-5a
v0.6.0-rc-5
v0.6.0-rc-4
v0.6.0-rc-3
v0.6.0-rc-2
v0.6.0-rc-1
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
