Merge pull request #889 from qdrant/feat/mac/CVE-2024-3829

Announcement for CVE-2024-3829
This commit is contained in:
David Myriel
2024-06-10 10:13:22 -07:00
committed by GitHub
3 changed files with 72 additions and 5 deletions
@@ -3,7 +3,7 @@ title: "Response to CVE-2024-2221: Arbitrary file upload vulnerability"
draft: false
slug: cve-2024-2221-response
short_description: Qdrant keeps your systems secure
description: Upgrade your deployments to at least v1.8.0. Cloud deployments not materially affected.
description: Upgrade your deployments to at least v1.9.0. Cloud deployments not materially affected.
preview_image: /blog/cve-2024-2221/cve-2024-2221-response-social-preview.png
# social_preview_image: /blog/Article-Image.png # Optional image used for link previews
@@ -22,7 +22,7 @@ weight: 0 # Change this weight to change order of posts
### Summary
A security vulnerability has been discovered in Qdrant affecting all versions
prior to v1.8, described in [CVE-2024-2221](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2221).
prior to v1.9, described in [CVE-2024-2221](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2221).
The vulnerability allows an attacker to upload arbitrary files to the
filesystem, which can be used to gain remote code execution.
@@ -31,13 +31,13 @@ filesystem is read-only and authentication is enabled by default. At worst,
the vulnerability could be used by an authenticated user to crash a cluster,
which is already possible, such as by uploading more vectors than can fit in RAM.
Qdrant has addressed the vulnerability in v1.8.3 and above with code that
Qdrant has addressed the vulnerability in v1.9.0 and above with code that
restricts file uploads to a folder dedicated to that purpose.
### Action
Check the current version of your Qdrant deployment. Upgrade if your deployment
is not at least v1.8.3.
is not at least v1.9.0.
To confirm the version of your Qdrant deployment in the cloud or on your local
or cloud system, run an API GET call, as described in the [Qdrant Quickstart
@@ -58,8 +58,10 @@ guide. The default commands automatically pull the latest version of Qdrant.
If you’ve set up Qdrant on kubernetes using a helm chart, follow the README in
the [qdrant-helm](https://github.com/qdrant/qdrant-helm/tree/main?tab=readme-ov-file#upgrading) repository.
Make sure applicable configuration files point to version v1.8.3 or above.
Make sure applicable configuration files point to version v1.9.0 or above.
#### If you use the Qdrant cloud
No action is required. This vulnerability does not materially affect you. However, we suggest that you upgrade your cloud deployment to the latest version.
> Note: This article has been updated on 2024-05-10 to encourage users to upgrade to 1.9.0 to ensure protection from both CVE-2024-2221 and CVE-2024-3829.
@@ -0,0 +1,65 @@
---
title: "Response to CVE-2024-3829: Arbitrary file upload vulnerability"
draft: false
slug: cve-2024-3829-response
short_description: Qdrant keeps your systems secure
description: Upgrade your deployments to at least v1.9.0. Cloud deployments not materially affected.
preview_image: /blog/cve-2024-3829-response/cve-2024-3829-response-social-preview.png
# social_preview_image: /blog/Article-Image.png # Optional image used for link previews
# title_preview_image: /blog/Article-Image.png # Optional image used for blog post title
# small_preview_image: /blog/Article-Image.png # Optional image used for small preview in the list of blog posts
date: 2024-06-10T17:00:00Z
author: Mac Chaffee
featured: false
tags:
- cve
- security
weight: 0 # Change this weight to change order of posts
# For more guidance, see https://github.com/qdrant/landing_page?tab=readme-ov-file#blog
---
### Summary
A security vulnerability has been discovered in Qdrant affecting all versions
prior to v1.9, described in [CVE-2024-3829](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3829).
The vulnerability allows an attacker to upload arbitrary files to the
filesystem, which can be used to gain remote code execution. This is a different but similar vulnerability to CVE-2024-2221, announced in April 2024.
The vulnerability does not materially affect Qdrant cloud deployments, as that
filesystem is read-only and authentication is enabled by default. At worst,
the vulnerability could be used by an authenticated user to crash a cluster,
which is already possible, such as by uploading more vectors than can fit in RAM.
Qdrant has addressed the vulnerability in v1.9.0 and above with code that
restricts file uploads to a folder dedicated to that purpose.
### Action
Check the current version of your Qdrant deployment. Upgrade if your deployment
is not at least v1.9.0.
To confirm the version of your Qdrant deployment in the cloud or on your local
or cloud system, run an API GET call, as described in the [Qdrant Quickstart
guide](https://qdrant.tech/documentation/cloud/quickstart-cloud/#step-2-test-cluster-access).
If your Qdrant deployment is local, you do not need an API key.
Your next step depends on how you installed Qdrant. For details, read the
[Qdrant Installation](https://qdrant.tech/documentation/guides/installation/)
guide.
#### If you use the Qdrant container or binary
Upgrade your deployment. Run the commands in the applicable section of the
[Qdrant Installation](https://qdrant.tech/documentation/guides/installation/)
guide. The default commands automatically pull the latest version of Qdrant.
#### If you use the Qdrant helm chart
If you’ve set up Qdrant on kubernetes using a helm chart, follow the README in
the [qdrant-helm](https://github.com/qdrant/qdrant-helm/tree/main?tab=readme-ov-file#upgrading) repository.
Make sure applicable configuration files point to version v1.9.0 or above.
#### If you use the Qdrant cloud
No action is required. This vulnerability does not materially affect you. However, we suggest that you upgrade your cloud deployment to the latest version.
Binary file not shown.

After

Width:  |  Height:  |  Size: 608 KiB