High severity7.5NVD Advisory· Published May 30, 2024· Updated Jun 17, 2026
CVE-2024-3584
CVE-2024-3584
Description
qdrant/qdrant version 1.9.0-dev is vulnerable to path traversal due to improper input validation in the /collections/{name}/snapshots/upload endpoint. By manipulating the name parameter through URL encoding, an attacker can upload a file to an arbitrary location on the system, such as /root/poc.txt. This vulnerability allows for the writing and overwriting of arbitrary files on the server, potentially leading to a full takeover of the system. The issue is fixed in version 1.9.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
qdrantcrates.io | >= 1.9.0-dev, < 1.9.0 | 1.9.0 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/qdrant/qdrant/commit/15479a45ffa3b955485ae516696f7e933a8cce8anvdPatchWEB
- huntr.com/bounties/5c7c82e2-4873-40b7-a5f3-0f4a42642f73nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-xcr2-h8hv-6227ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-3584ghsaADVISORY
News mentions
0No linked articles in our index yet.