S4E just found a low-severity finding from [ai] web application external link detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-31856 Scanner

CVE-2021-31856 scanner - SQL Injection (SQLi) vulnerability in Layer5 Meshery

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-31856
9.8
CVSS

A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the /experimental/patternfiles endpoint (order parameter in GetMesheryPatterns in models/meshery_pattern_persister.go).

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Layer5 Meshery is a service mesh management plane that is used to monitor, validate and manage the performance, behavior and configuration of service meshes like Istio, Linkerd, Consul and others. The goal of Meshery is to facilitate integrating and operating service meshes seamlessly and reliably. It's designed with Kubernetes in mind and automates several complex operations that operators, developers and architects face when using Kubernetes and Service Mesh together.

CVE-2021-31856 is a critical vulnerability detected in Layer5 Meshery 0.5.2, posing a significant threat to security. An attacker can use the REST API of Meshery via the experimental/patternfiles endpoint to inject arbitrary SQL commands. An order parameter in GetMesheryPatterns in the models/meshery_pattern_persister.go file can be exploited for this purpose. The attacker can then execute malicious SQL commands through the endpoint, leading to the unauthorized access, manipulation and deletion of data.

The exploitation of CVE-2021-31856 could lead to serious consequences such as data manipulation, data theft and denial-of-service attacks. Attackers can use the vulnerability to infiltrate and compromise critical systems and sensitive data. The ability to execute arbitrary SQL commands through Meshery's REST API means that any data stored in the backend database, including configurations, logs, and credentials, is at risk of unauthorised access, modification or exfiltration.

s4e.io is a powerful analytical platform for discovering and analyzing security vulnerabilities in digital assets. Thanks to its premium features, such as vulnerability management and threat intelligence, readers of this article can easily and quickly learn about vulnerabilities in their digital assets and take necessary precautions to avoid exploitation. The Platform is designed to provide complete visibility, allowing for comprehensive risk management of the assets and applications. Security is not a one-time event, but a continuous process that requires vigilance and a proactive approach.

 

REFERENCES

Solution Advice

Precautions can be taken to protect against CVE-2021-31856 by following some best practices, including:

  • Upgrading to the latest version of Meshery;
  • Ensuring Secure Coding Practices  by reviewing the codebase for similar vulnerabilities;
  • Auditing the source code and checking for vulnerabilities in third-party dependencies;
  • Enforcing least privilege access control principles to limit access to the REST API;
  • Setting up intrusion detection and prevention systems for detecting and blocking unauthorized access;
  • Restricting network traffic access using firewalls and access control policies.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.