← Qdrant

2024 Qdrant — CVE-2024-2221 arbitrary file upload; CVE-2024-3829 critical

2024 Unknown records affected Share on X

Data compromised

Potential: file system access; data exfiltration

Technical writeup

CVE-2024-2221: arbitrary file upload. CVE-2024-3829: arbitrary file read/write during snapshot recovery (CVSS 9.1). CVE-2024-3584: path traversal. Vector DB used widely for AI workloads.

Root cause

Input validation flaws; insecure file handling

References