Weaviate security release - Medium and High severity fixes for CVEs
Article excerpt
Highlighted: the sentence this signal was extracted from
Weaviate security release - medium and high severity fixes for CVEs. This week Weaviate has released security patches for Weaviate 1.30.x, 1.31.x, 1.32.x and 1.33.x. These patches contain a fix for two pending CVEs (Weaviate will update this blog once Weaviate has had CVEs reserved), a high severity path traversal vulnerability in its backup modules, and a medium severity path traversal vulnerability in its shard movement module. As per its security policy, Weaviate customers running in Weaviate Cloud, and Marketplace customers on AWS, Azure and GCP have been patched seamlessly. Its Weaviate Enterprise Support customers have received early notification under embargo. Path traversal via backup zipslip (CVE pending). An attacker with access to create objects in Weaviate can use symbolic links, absolute paths or "..." segments to escape the intended restore root for backups, and create or overwrite files at arbitrary paths within Weaviate's privilege scope. The CVSS score for this vulnerability is High (7.2) Impacted versions of Weaviate are <= Weaviate 1.30.19, <= Weaviate 1.31.18, <= Weaviate 1.32.15 and <= Weaviate 1.33.3. Weaviate recommend that impacted customers update their Weaviate installations to fully address the vulnerability. The Backup modules can also be disabled by removing any backup* entries from the "enabled_modules" flag. Path traversal via Shard...
Keep reading with a free account
The rest of this article, and every signal for Weaviate, is in your free account.
