qdrant-client@1.2.0 vulnerabilities

Client library for the Qdrant vector search engine

  • latest version

    1.13.2

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    26 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the qdrant-client package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Improper Input Validation

    qdrant-client is a Client library for the Qdrant vector search engine

    Affected versions of this package are vulnerable to Improper Input Validation through the snapshot recovery process. An attacker can read and write arbitrary files on the server by manipulating snapshot files to include symlinks, leading to arbitrary file read by adding a symlink that points to a desired file on the filesystem and arbitrary file write by including a symlink and a payload file in the snapshot's directory structure. This vulnerability allows for the reading and writing of arbitrary files on the server, which could potentially lead to a full takeover of the system.

    How to fix Improper Input Validation?

    Upgrade qdrant-client to version 1.9.0 or higher.

    [,1.9.0)