We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-6583

Path Traversal in stangirard/quivr



Description

A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker to upload files to arbitrary paths in an S3 bucket by manipulating the file path in the upload request.

Reserved 2024-07-08 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_ai


MEDIUM: 4.3CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Problem types

CWE-23 Relative Path Traversal

Product status

Any version
affected

References

huntr.com/bounties/c310b500-ec26-4121-8d3a-8e863181346f

cve.org (CVE-2024-6583)

nvd.nist.gov (CVE-2024-6583)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-6583

Support options

Helpdesk Chat, Email, Knowledgebase