2024 Qdrant — CVE-2024-2221 arbitrary file upload; CVE-2024-3829 critical
Data compromised
Potential: file system access; data exfiltration
Technical writeup
CVE-2024-2221: arbitrary file upload. CVE-2024-3829: arbitrary file read/write during snapshot recovery (CVSS 9.1). CVE-2024-3584: path traversal. Vector DB used widely for AI workloads.
Root cause
Input validation flaws; insecure file handling