PT-2024-3893 · Ollama · Ollama

Published

2024-03-08

·

Updated

2024-06-10

·

CVE-2024-28224

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Ollama versions prior to 0.1.29
Description: The issue is related to a DNS rebinding vulnerability that can inadvertently allow remote access to the full API. This vulnerability can let an unauthorized user chat with a large language model, delete a model, or cause a denial of service due to resource exhaustion. The vulnerability is associated with the use of reverse DNS resolution for IP addresses and can be exploited by a remote attacker to perform a DNS rebinding attack.
Recommendations: For versions prior to 0.1.29, update to version 0.1.29 or later to resolve the issue. As a temporary workaround, consider restricting access to the API to minimize the risk of exploitation. Avoid using the API for critical operations until the issue is resolved. At the moment, there is no other information about additional mitigation measures.

Fix

Origin Validation Error

Protection Mechanism Failure

Information Disclosure

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2024-04299
CVE-2024-28224
GHSA-5JX5-HQX5-2VRJ
GO-2024-2699

Affected Products

Ollama