mirror of
https://github.com/qdrant/landing_page.git
synced 2026-09-30 16:38:31 +02:00
Announcement for CVE-2024-3829
This commit is contained in:
@@ -3,7 +3,7 @@ title: "Response to CVE-2024-2221: Arbitrary file upload vulnerability"
|
||||
draft: false
|
||||
slug: cve-2024-2221-response
|
||||
short_description: Qdrant keeps your systems secure
|
||||
description: Upgrade your deployments to at least v1.8.0. Cloud deployments not materially affected.
|
||||
description: Upgrade your deployments to at least v1.9.0. Cloud deployments not materially affected.
|
||||
preview_image: /blog/cve-2024-2221/cve-2024-2221-response-social-preview.png
|
||||
|
||||
# social_preview_image: /blog/Article-Image.png # Optional image used for link previews
|
||||
@@ -22,7 +22,7 @@ weight: 0 # Change this weight to change order of posts
|
||||
### Summary
|
||||
|
||||
A security vulnerability has been discovered in Qdrant affecting all versions
|
||||
prior to v1.8, described in [CVE-2024-2221](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2221).
|
||||
prior to v1.9, described in [CVE-2024-2221](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2221).
|
||||
The vulnerability allows an attacker to upload arbitrary files to the
|
||||
filesystem, which can be used to gain remote code execution.
|
||||
|
||||
@@ -31,13 +31,13 @@ filesystem is read-only and authentication is enabled by default. At worst,
|
||||
the vulnerability could be used by an authenticated user to crash a cluster,
|
||||
which is already possible, such as by uploading more vectors than can fit in RAM.
|
||||
|
||||
Qdrant has addressed the vulnerability in v1.8.3 and above with code that
|
||||
Qdrant has addressed the vulnerability in v1.9.0 and above with code that
|
||||
restricts file uploads to a folder dedicated to that purpose.
|
||||
|
||||
### Action
|
||||
|
||||
Check the current version of your Qdrant deployment. Upgrade if your deployment
|
||||
is not at least v1.8.3.
|
||||
is not at least v1.9.0.
|
||||
|
||||
To confirm the version of your Qdrant deployment in the cloud or on your local
|
||||
or cloud system, run an API GET call, as described in the [Qdrant Quickstart
|
||||
@@ -58,8 +58,10 @@ guide. The default commands automatically pull the latest version of Qdrant.
|
||||
|
||||
If you’ve set up Qdrant on kubernetes using a helm chart, follow the README in
|
||||
the [qdrant-helm](https://github.com/qdrant/qdrant-helm/tree/main?tab=readme-ov-file#upgrading) repository.
|
||||
Make sure applicable configuration files point to version v1.8.3 or above.
|
||||
Make sure applicable configuration files point to version v1.9.0 or above.
|
||||
|
||||
#### If you use the Qdrant cloud
|
||||
|
||||
No action is required. This vulnerability does not materially affect you. However, we suggest that you upgrade your cloud deployment to the latest version.
|
||||
|
||||
> Note: This article has been updated on 2024-05-10 to encourage users to upgrade to 1.9.0 to ensure protection from both CVE-2024-2221 and CVE-2024-3829.
|
||||
|
||||
@@ -0,0 +1,65 @@
|
||||
---
|
||||
title: "Response to CVE-2024-3829: Arbitrary file upload vulnerability"
|
||||
draft: false
|
||||
slug: cve-2024-3829-response
|
||||
short_description: Qdrant keeps your systems secure
|
||||
description: Upgrade your deployments to at least v1.9.0. Cloud deployments not materially affected.
|
||||
preview_image: /blog/cve-2024-3829/cve-2024-3829-response-social-preview.png
|
||||
|
||||
# social_preview_image: /blog/Article-Image.png # Optional image used for link previews
|
||||
# title_preview_image: /blog/Article-Image.png # Optional image used for blog post title
|
||||
# small_preview_image: /blog/Article-Image.png # Optional image used for small preview in the list of blog posts
|
||||
date: 2024-05-10T13:00:00-07:00
|
||||
author: Mac Chaffee
|
||||
featured: false
|
||||
tags:
|
||||
- cve
|
||||
- security
|
||||
weight: 0 # Change this weight to change order of posts
|
||||
# For more guidance, see https://github.com/qdrant/landing_page?tab=readme-ov-file#blog
|
||||
---
|
||||
|
||||
### Summary
|
||||
|
||||
A security vulnerability has been discovered in Qdrant affecting all versions
|
||||
prior to v1.9, described in [CVE-2024-3829](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3829).
|
||||
The vulnerability allows an attacker to upload arbitrary files to the
|
||||
filesystem, which can be used to gain remote code execution. This is a different but similar vulnerability to CVE-2024-2221, announced in April 2024.
|
||||
|
||||
The vulnerability does not materially affect Qdrant cloud deployments, as that
|
||||
filesystem is read-only and authentication is enabled by default. At worst,
|
||||
the vulnerability could be used by an authenticated user to crash a cluster,
|
||||
which is already possible, such as by uploading more vectors than can fit in RAM.
|
||||
|
||||
Qdrant has addressed the vulnerability in v1.9.0 and above with code that
|
||||
restricts file uploads to a folder dedicated to that purpose.
|
||||
|
||||
### Action
|
||||
|
||||
Check the current version of your Qdrant deployment. Upgrade if your deployment
|
||||
is not at least v1.9.0.
|
||||
|
||||
To confirm the version of your Qdrant deployment in the cloud or on your local
|
||||
or cloud system, run an API GET call, as described in the [Qdrant Quickstart
|
||||
guide](https://qdrant.tech/documentation/cloud/quickstart-cloud/#step-2-test-cluster-access).
|
||||
If your Qdrant deployment is local, you do not need an API key.
|
||||
|
||||
Your next step depends on how you installed Qdrant. For details, read the
|
||||
[Qdrant Installation](https://qdrant.tech/documentation/guides/installation/)
|
||||
guide.
|
||||
|
||||
#### If you use the Qdrant container or binary
|
||||
|
||||
Upgrade your deployment. Run the commands in the applicable section of the
|
||||
[Qdrant Installation](https://qdrant.tech/documentation/guides/installation/)
|
||||
guide. The default commands automatically pull the latest version of Qdrant.
|
||||
|
||||
#### If you use the Qdrant helm chart
|
||||
|
||||
If you’ve set up Qdrant on kubernetes using a helm chart, follow the README in
|
||||
the [qdrant-helm](https://github.com/qdrant/qdrant-helm/tree/main?tab=readme-ov-file#upgrading) repository.
|
||||
Make sure applicable configuration files point to version v1.9.0 or above.
|
||||
|
||||
#### If you use the Qdrant cloud
|
||||
|
||||
No action is required. This vulnerability does not materially affect you. However, we suggest that you upgrade your cloud deployment to the latest version.
|
||||
Reference in New Issue
Block a user