SCA: security update for qdrant-client (GHSA-7m75-x27w-r52r)

critical Tenable Self-Hosted Container Security Plugin ID 412129

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- qdrant/qdrant version 1.9.0-dev is vulnerable to arbitrary file read and write during the snapshot
recovery process. Attackers can exploit this vulnerability by manipulating snapshot files to include
symlinks, leading to arbitrary file read by adding a symlink that points to a desired file on the
filesystem and arbitrary file write by including a symlink and a payload file in the snapshot's directory
structure. This vulnerability allows for the reading and writing of arbitrary files on the server, which
could potentially lead to a full takeover of the system. The issue is fixed in version v1.9.0.
(CVE-2024-3829)

See Also

https://github.com/advisories/GHSA-7m75-x27w-r52r

Plugin Details

Severity: Critical

ID: 412129

Version: Revision 1.14

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 6/1/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.0

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2024-3829

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/3/2024

Vulnerability Publication Date: 6/3/2024

Reference Information

CVE: CVE-2024-3829