PT-2024-9415 · Ollama · Ollama

Published

2024-10-30

·

Updated

2025-02-27

·

CVE-2024-39719

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ollama versions 0.3.14 and earlier
Description The issue is related to the disclosure of system data to unauthorized individuals. It can be exploited by a remote attacker to cause a denial of service. The vulnerability allows file existence disclosure via the "api/create" endpoint. When the CreateModel route is called with a path parameter that does not exist, it reflects the "File does not exist" error message to the attacker, providing information about file existence on the server.
Recommendations For Ollama versions 0.3.14 and earlier, update to version 0.1.47 or later to protect against file disclosure risks. As a temporary workaround, consider restricting access to the "api/create" endpoint until a patch is available. Avoid using the CreateModel route with path parameters that do not exist to minimize the risk of exploitation.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2024-11110
CVE-2024-39719

Affected Products

Ollama