Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hm95-xqg2-4w57

Опубликовано: 10 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the /collections/{COLLECTION}/snapshots/upload endpoint, specifically through the snapshot parameter. This vulnerability allows attackers to upload and overwrite any file on the filesystem, leading to potential remote code execution. This issue affects the integrity and availability of the system, enabling unauthorized access and potentially causing the server to malfunction.

qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the /collections/{COLLECTION}/snapshots/upload endpoint, specifically through the snapshot parameter. This vulnerability allows attackers to upload and overwrite any file on the filesystem, leading to potential remote code execution. This issue affects the integrity and availability of the system, enabling unauthorized access and potentially causing the server to malfunction.

EPSS

Процентиль: 96%
0.25531
Средний

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
почти 2 года назад

qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTION}/snapshots/upload` endpoint, specifically through the `snapshot` parameter. This vulnerability allows attackers to upload and overwrite any file on the filesystem, leading to potential remote code execution. This issue affects the integrity and availability of the system, enabling unauthorized access and potentially causing the server to malfunction.

EPSS

Процентиль: 96%
0.25531
Средний

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-434