VYPR
Critical severity9.1NVD Advisory· Published Jun 3, 2024· Updated Jun 17, 2026

CVE-2024-3829

CVE-2024-3829

Description

qdrant/qdrant version 1.9.0-dev is vulnerable to arbitrary file read and write during the snapshot recovery process. Attackers can exploit this vulnerability by manipulating snapshot files to include symlinks, leading to arbitrary file read by adding a symlink that points to a desired file on the filesystem and arbitrary file write by including a symlink and a payload file in the snapshot's directory structure. This vulnerability allows for the reading and writing of arbitrary files on the server, which could potentially lead to a full takeover of the system. The issue is fixed in version v1.9.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
qdrant-clientPyPI
< 1.9.01.9.0

Affected products

3
  • Qdrant/Qdrant2 versions
    cpe:2.3:a:qdrant:qdrant:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:qdrant:qdrant:*:*:*:*:*:*:*:*range: <1.9.0
    • (no CPE)range: unspecified
  • ghsa-coords
    Range: < 1.9.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.