CVE-2024-6583

Severity CVSS v4.0:
Pending analysis
Type:
CWE-23 Relative Path Traversal
Publication date:
20/03/2025
Last modified:
15/07/2025

Description

A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker to upload files to arbitrary paths in an S3 bucket by manipulating the file path in the upload request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:quivr:quivr:0.0.254:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools