Home / Companies / Qdrant / Blog / Post Details
Content Deep Dive

Response to CVE-2024-2221: Arbitrary file upload vulnerability

Blog post from Qdrant

Post Details
Company
Date Published
Author
Mike Jang
Word Count
346
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

A security vulnerability identified as CVE-2024-2221 has been discovered in Qdrant, affecting all versions before v1.9. This vulnerability permits attackers to upload arbitrary files, potentially leading to remote code execution. However, it poses minimal risk to Qdrant cloud deployments, as the filesystem is read-only and authentication is enabled by default. The issue has been resolved in Qdrant v1.9.0 and later, which restricts file uploads to a specific folder. Users are advised to check their current Qdrant version and upgrade to at least v1.9.0 if necessary. While no action is needed for those using Qdrant cloud, upgrading to the latest version is recommended for comprehensive protection, including against another vulnerability, CVE-2024-3829.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 1 2,064 236 94 +7%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.