HIGH8.8
GHSA-5jx5-hqx5-2vrj
Ollama DNS rebinding vulnerability
Quick fix
GHSA-5jx5-hqx5-2vrj — github.com/ollama/ollama: upgrade to the fixed version with the command below.
go get github.com/ollama/ollama@v0.1.29Details
Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model, or cause a denial of service (resource exhaustion).
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/ollama/ollama
Introduced in:
0Fixed in: 0.1.29Fix
go get github.com/ollama/ollama@v0.1.29References
- https://nvd.nist.gov/vuln/detail/CVE-2024-28224[ADVISORY]
- https://github.com/ollama/ollama[PACKAGE]
- https://github.com/ollama/ollama/releases[WEB]
- https://pkg.go.dev/vuln/GO-2024-2699[WEB]
- https://research.nccgroup.com/2024/04/08/technical-advisory-ollama-dns-rebinding-attack-cve-2024-28224[WEB]
- https://www.nccgroup.trust/us/our-research/?research=Technical+advisories[WEB]