← back
CVE-2024-2221

Path Traversal and Arbitrary File Upload Vulnerability in qdrant/qdrant

CVSS 9.8 CRITICALEPSS 1.8%CWE-434
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.8EPSS 1.8%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
10 Apr 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTION}/snapshots/upload` endpoint, specifically through the `snapshot` parameter. This vulnerability allows attackers to upload and overwrite any file on the filesystem, leading to potential remote code execution. This issue affects the integrity and availability of the system, enabling unauthorized access and potentially causing the server to malfunction.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
qdrant · qdrant/qdrant

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →