漏洞描述
Qdrant UI Dashboard was detected and appeared to be accessible without authentication.
id: unauth-qdrantui
info:
name: Qdrant UI - Unauthenticated Access
author: DhiyaneshDk
severity: high
description: |
Qdrant UI Dashboard was detected and appeared to be accessible without authentication.
classification:
cwe-id: CWE-200
metadata:
verified: true
max-request: 1
shodan-query: html:"qdrant - vector search engine"
tags: qdrant,misconfig,unauth,vuln
http:
- method: GET
path:
- "{{BaseURL}}/collections"
matchers:
- type: dsl
dsl:
- 'contains_all(body, "\"result\":{", "\"collections\":[", "\"status\":\"ok\"")'
- 'status_code == 200'
condition: and
# digest: 4b0a00483046022100b68d743e3af5372fe68f48f04d894304aa7327dd59f613fc775ad806fd9bc37b02210090ceb01d8f86d3d590791c70c51f9cf58bfc9c2aa9406de6ba319a58057cb26d:922c64590222798bb761d5b6d8e72950