Files
landing_page/qdrant-landing/content/blog/cve-2024-2221-response.md
T
Bastian Hofmann 5ca363a439 Improvement to Cloud and Hybrid Cloud docs
This significantly improves our cloud and hybrid cloud docs:

* Adds screenshots
* Better structure
* More information about payments, including stripe and azure marketplace
* Better cluster creation docs
* Account setup and invitation docs
* Monitoring docs
* Cluster upgrade docs
* Support docs
* Removed duplications
2024-08-15 17:31:04 +02:00

68 lines
3.0 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
title: "Response to CVE-2024-2221: Arbitrary file upload vulnerability"
draft: false
slug: cve-2024-2221-response
short_description: Qdrant keeps your systems secure
description: Upgrade your deployments to at least v1.9.0. Cloud deployments not materially affected.
preview_image: /blog/cve-2024-2221/cve-2024-2221-response-social-preview.png
# social_preview_image: /blog/Article-Image.png # Optional image used for link previews
# title_preview_image: /blog/Article-Image.png # Optional image used for blog post title
# small_preview_image: /blog/Article-Image.png # Optional image used for small preview in the list of blog posts
date: 2024-04-05T13:00:00-07:00
author: Mike Jang
featured: false
tags:
- cve
- security
weight: 0 # Change this weight to change order of posts
# For more guidance, see https://github.com/qdrant/landing_page?tab=readme-ov-file#blog
---
### Summary
A security vulnerability has been discovered in Qdrant affecting all versions
prior to v1.9, described in [CVE-2024-2221](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2221).
The vulnerability allows an attacker to upload arbitrary files to the
filesystem, which can be used to gain remote code execution.
The vulnerability does not materially affect Qdrant cloud deployments, as that
filesystem is read-only and authentication is enabled by default. At worst,
the vulnerability could be used by an authenticated user to crash a cluster,
which is already possible, such as by uploading more vectors than can fit in RAM.
Qdrant has addressed the vulnerability in v1.9.0 and above with code that
restricts file uploads to a folder dedicated to that purpose.
### Action
Check the current version of your Qdrant deployment. Upgrade if your deployment
is not at least v1.9.0.
To confirm the version of your Qdrant deployment in the cloud or on your local
or cloud system, run an API GET call, as described in the [Qdrant Cloud Setup
guide](/documentation/cloud/authentication/#test-cluster-access).
If your Qdrant deployment is local, you do not need an API key.
Your next step depends on how you installed Qdrant. For details, read the
[Qdrant Installation](/documentation/guides/installation/)
guide.
#### If you use the Qdrant container or binary
Upgrade your deployment. Run the commands in the applicable section of the
[Qdrant Installation](/documentation/guides/installation/)
guide. The default commands automatically pull the latest version of Qdrant.
#### If you use the Qdrant helm chart
If you’ve set up Qdrant on kubernetes using a helm chart, follow the README in
the [qdrant-helm](https://github.com/qdrant/qdrant-helm/tree/main?tab=readme-ov-file#upgrading) repository.
Make sure applicable configuration files point to version v1.9.0 or above.
#### If you use the Qdrant cloud
No action is required. This vulnerability does not materially affect you. However, we suggest that you upgrade your cloud deployment to the latest version.
> Note: This article has been updated on 2024-05-10 to encourage users to upgrade to 1.9.0 to ensure protection from both CVE-2024-2221 and CVE-2024-3829.