Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model, or cause a denial of service (resource exhaustion).
CVSS
No CVSS.
References
Configurations
History
13 May 2025, 00:42
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:* | |
First Time |
Ollama ollama
Ollama |
|
References | () https://research.nccgroup.com/2024/04/08/technical-advisory-ollama-dns-rebinding-attack-cve-2024-28224/ - Not Applicable | |
References | () https://www.nccgroup.trust/us/our-research/?research=Technical+advisories - Broken Link | |
References | () https://github.com/ollama/ollama/releases - Release Notes |
08 Apr 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-08 19:15
Updated : 2025-05-13 00:42
NVD link : CVE-2024-28224
Mitre link : CVE-2024-28224
JSON object : View
Products Affected
ollama
- ollama
CWE
No CWE.