Complete info per discussion

This commit is contained in:
mjang
2024-03-13 08:03:26 -07:00
parent 18f90d2fe5
commit e923573261
4 changed files with 103 additions and 37 deletions
@@ -1,59 +1,66 @@
---
title: "Qdrant’s Response to CVE-2024-2221: Arbitrary file upload vulnerability"
title: "Response to CVE-2024-2221: Arbitrary file upload vulnerability"
draft: false
slug: cve-2024-2221-response
short_description: Qdrant keeps your systems secure
description: Upgrade your deployments to at least v1.8.0. Cloud systems not materially affected.
preview_image: /blog/Article-Image.png # Change this
preview_image: /blog/cve-2024-2221/cve-2024-2221-response-social-preview.png
# social_preview_image: /blog/Article-Image.png # Optional image used for link previews
# title_preview_image: /blog/Article-Image.png # Optional image used for blog post title
# small_preview_image: /blog/Article-Image.png # Optional image used for small preview in the list of blog posts
<!-- MUSTFIX: change date before merging -->
date: 2024-03-13T06:42:06-07:00
author: John Doe # Change this
featured: false # if true, this post will be featured on the blog page
tags: # Change this, related by tags posts will be shown on the blog page
- news
- blog
author: Mike Jang
featured: false
tags:
- cve
- security
weight: 0 # Change this weight to change order of posts
# For more guidance, see https://github.com/qdrant/landing_page?tab=readme-ov-file#blog
---
Here is your blog post content. You can use markdown syntax here.
### Summary
# Header 1
## Header 2
### Header 3
#### Header 4
##### Header 5
###### Header 6
A security vulnerability has been discovered in Qdrant affecting all versions
prior to v1.8, described in [CVE-2024-2221](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2221).
The vulnerability allows an attacker to upload arbitrary files to the
filesystem, which can be used to gain remote code execution.
<aside role="alert">
You can add a note to your page using this aside block.
</aside>
The vulnerability does not materially affect Qdrant cloud deployments, as that
filesystem is read-only and authentication is enabled by default. At worst,
the vulnerability could be used by an authenticated user to crash a cluster,
which is already possible, such as by uploading more vectors than can fit in RAM.
<aside role="status">
This is a warning message.
</aside>
Qdrant has addressed the vulnerability in v1.8.0 and above with code that
restricts file uploads to a folder dedicated to that purpose.
> This is a blockquote following a header.
### Action
Table:
Check the current version of your Qdrant deployment. Upgrade if your deployment
is not at least v1.8.0.
| Header 1 | Header 2 | Header 3 | Header 4 |
| -------- | -------- | -------- | -------- |
| Cell 1 | Cell 2 | Cell 3 | Cell 4 |
| Cell 3 | Cell 4 | Cell 5 | Cell 6 |
To confirm the version of your Qdrant deployment in the cloud or on your local
or cloud system, run an API GET call, as described in the [Qdrant Quickstart
guide](https://qdrant.tech/documentation/cloud/quickstart-cloud/#step-2-test-cluster-access).
If your Qdrant deployment is local, you do not need an API key.
- List item 1
- Nested list item 1
- Nested list item 2
- List item 2
- List item 3
Your next step depends on how you installed Qdrant. For details, read the
[Qdrant Installation](https://qdrant.tech/documentation/guides/installation/)
guide.
1. Numbered list item 1
1. Nested numbered list item 1
2. Nested numbered list item 2
2. Numbered list item 2
3. Numbered list item 3
#### If you use the Qdrant container or binary
Upgrade your deployment. Run the commands in the applicable section of the
[Qdrant Installation](https://qdrant.tech/documentation/guides/installation/)
guide. The default commands automatically pull the latest version of Qdrant.
#### If you use the Qdrant helm chart
If you’ve set up Qdrant on kubernetes using a helm chart, follow the README in
the [qdrant-helm](https://github.com/qdrant/qdrant-helm/tree/main?tab=readme-ov-file#upgrading) repository.
Make sure applicable configuration files point to version v1.8.0 or above.
#### If you use the Qdrant cloud
No action is required. This vulnerability does not materially affect you. However, we suggest that you upgrade your cloud deployment to the latest version.