GPU VulnDB

Database/AI/ML frameworks & serving

Qdrant (snapshot upload): Path traversal + arbitrary file upload via `/collections/{c}/snapshots/upload`

CVE-2024-2221AI/ML frameworks & servingcurated

Impact

Path traversal + arbitrary file upload via /collections/{c}/snapshots/upload

Who can reach it

Network user able to upload a snapshot

What to do

Upgrade; snapshot upload is an arbitrary-write primitive

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.