BlogsQdrantSecurity Vulnerability Response

Security Vulnerability Response

Security Vulnerability Response

2
posts
2024

Qdrant has addressed a critical arbitrary file upload vulnerability (CVE-2024-2221) in versions prior to v1.9.0. The fix restricts file uploads to a dedicated folder. Qdrant cloud deployments were not materially affected due to read-only filesystems and default authentication. Users are advised to upgrade to v1.9.0 or above. This update also incorporates a fix for CVE-2024-3829, further enhancing security.

2024

Response to CVE-2024-3829: Arbitrary file upload vulnerability - Qdrant

6/10/2024

This post details the response to CVE-2024-3829, an arbitrary file upload vulnerability. It explains the vulnerability, its impact, and the mitigation implemented in Qdrant v1.9.0, which restricts file uploads to a dedicated directory. It also clarifies the impact on Qdrant cloud deployments and provides upgrade instructions for users of container, binary, and helm chart installations.

Response to CVE-2024-2221: Arbitrary file upload vulnerability - Qdrant

4/5/2024

This post details the response to CVE-2024-2221, an arbitrary file upload vulnerability. The fix involves restricting file uploads to a dedicated folder in versions v1.9.0 and above. It also notes that Qdrant cloud deployments were not materially affected due to read-only filesystems and default authentication. The post advises users to upgrade to v1.9.0 or above and provides instructions for different installation methods (container, binary, helm chart, cloud). An update on 2024-05-10 encourages upgrading to 1.9.0 to address both CVE-2024-2221 and CVE-2024-3829.