Vulnerability Description
Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model, or cause a denial of service (resource exhaustion).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ollama | Ollama | < 0.1.29 |
Related Weaknesses (CWE)
References
- https://github.com/ollama/ollama/releasesRelease Notes
- https://research.nccgroup.com/2024/04/08/technical-advisory-ollama-dns-rebindingNot Applicable
- https://www.nccgroup.trust/us/our-research/?research=Technical+advisoriesBroken Link
- https://github.com/ollama/ollama/releasesRelease Notes
- https://research.nccgroup.com/2024/04/08/technical-advisory-ollama-dns-rebindingNot Applicable
- https://www.nccgroup.trust/us/our-research/?research=Technical+advisoriesBroken Link
FAQ
What is CVE-2024-28224?
CVE-2024-28224 is a vulnerability with a CVSS score of 6.6 (MEDIUM). Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model...
How severe is CVE-2024-28224?
CVE-2024-28224 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-28224?
Check the references section above for vendor advisories and patch information. Affected products include: Ollama Ollama.