Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the TestGetBlobsPath test cases such as fewer than 64 hex digits, more than 64 hex digits, or an initial ../ substring.
CVSS
No CVSS.
References
Configurations
History
01 May 2025, 14:01
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/ollama/ollama/blob/adeb40eaf29039b8964425f69a9315f9f1694ba8/server/modelpath_test.go#L41-L58 - Product | |
References | () https://www.vicarius.io/vsociety/posts/probllama-in-ollama-a-tale-of-a-yet-another-rce-vulnerability-cve-2024-37032 - Exploit, Third Party Advisory | |
References | () https://github.com/ollama/ollama/pull/4175 - Issue Tracking | |
References | () https://github.com/ollama/ollama/compare/v0.1.33...v0.1.34 - Release Notes | |
CPE | cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:* | |
First Time |
Ollama ollama
Ollama |
15 Jul 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
31 May 2024, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-31 04:15
Updated : 2025-05-01 14:01
NVD link : CVE-2024-37032
Mitre link : CVE-2024-37032
JSON object : View
Products Affected
ollama
- ollama
CWE
No CWE.