Author: Angelo Barbosa

CVE-2024-3078 | Qdrant up to 1.6.1/1.7.4/1.8.2 Full Snapshot REST API snapshots.rs path traversal (3856/3867)

A vulnerability was found in Qdrant up to 1.6.1/1.7.4/1.8.2 and classified as critical. This issue affects some unknown processing of the file lib/collection/src/collection/snapshots.rs of the component Full Snapshot REST API. The manipulation leads to path traversal. The identification of this vulnerability is CVE-2024-3078. The attack needs to be done within the local network. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-28960 | mbed TLS up to 2.28.7/3.5.x PSA Crypto API Privilege Escalation

A vulnerability has been found in mbed TLS up to 2.28.7/3.5.x and classified as problematic. This vulnerability affects unknown code of the component PSA Crypto API. The manipulation leads to Privilege Escalation. This vulnerability was named CVE-2024-28960. The attack can only be initiated within the local network. There is no exploit available. It is recommended to upgrade the affected...

Read More