Files
landing_page/qdrant-landing/content/blog/cve-2024-2221-response.md
T
1a40961d62 fix: linkchecker include filter port mismatch (#2242)
* initial commit; fixed anchor links on internal docs pages

* add back in absolute paths for links in code comments

* fix: update linkchecker include filter to match server port 1314

PR #1629 changed the Hugo server to port 1314 but forgot to update
the --include filter, which still matched port 1313. This caused all
links to be excluded, making the checker a no-op (0 checked, 82277 excluded).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Fix url rewrite regex so images are not impacted

* Fix links from non-documentation pages

* Fix broken links

* more broken links

* more broken links

* broken link

* Add srcset width descriptor to .lycheeignore

* Ignore URLs that contain a % character

* Anchor regex so it matches the entire URL

---------

Co-authored-by: kanungle <neil.kanungo@gmail.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Abdon Pijpelink <abdon.pijpelink@qdrant.com>
2026-03-30 17:21:32 +02:00

3.1 KiB
Raw Blame History

title, draft, slug, short_description, description, preview_image, date, author, featured, tags, weight
title draft slug short_description description preview_image date author featured tags weight
Response to CVE-2024-2221: Arbitrary file upload vulnerability false cve-2024-2221-response Qdrant keeps your systems secure Upgrade your deployments to at least v1.9.0. Cloud deployments not materially affected. /blog/cve-2024-2221/cve-2024-2221-response-social-preview.png 2024-04-05T13:00:00-07:00 Mike Jang false
cve
security
0

Summary

A security vulnerability has been discovered in Qdrant affecting all versions prior to v1.9, described in CVE-2024-2221. The vulnerability allows an attacker to upload arbitrary files to the filesystem, which can be used to gain remote code execution.

The vulnerability does not materially affect Qdrant cloud deployments, as that filesystem is read-only and authentication is enabled by default. At worst, the vulnerability could be used by an authenticated user to crash a cluster, which is already possible, such as by uploading more vectors than can fit in RAM.

Qdrant has addressed the vulnerability in v1.9.0 and above with code that restricts file uploads to a folder dedicated to that purpose.

Action

Check the current version of your Qdrant deployment. Upgrade if your deployment is not at least v1.9.0.

To confirm the version of your Qdrant deployment in the cloud or on your local or cloud system, run an API GET call, as described in the Qdrant Cloud Setup guide. If your Qdrant deployment is local, you do not need an API key.

Your next step depends on how you installed Qdrant. For details, read the Qdrant Installation guide.

If you use the Qdrant container or binary

Upgrade your deployment. Run the commands in the applicable section of the Qdrant Installation guide. The default commands automatically pull the latest version of Qdrant.

If you use the Qdrant helm chart

If you’ve set up Qdrant on kubernetes using a helm chart, follow the README in the qdrant-helm repository. Make sure applicable configuration files point to version v1.9.0 or above.

If you use the Qdrant cloud

No action is required. This vulnerability does not materially affect you. However, we suggest that you upgrade your cloud deployment to the latest version.

Note: This article has been updated on 2024-05-10 to encourage users to upgrade to 1.9.0 to ensure protection from both CVE-2024-2221 and CVE-2024-3829.