CVE-2024-28224: High severity Ollama Ollama vulnerability
Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model, or cause a denial of service (resource exhaustion).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/ollama/ollamato a version that resolves this vulnerability.Fixed in 0.1.29
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28224?
CVE-2024-28224 is considered a critical vulnerability due to its potential for unauthorized remote access to the API.
How do I fix CVE-2024-28224?
To fix CVE-2024-28224, upgrade to Ollama version 0.1.29 or later.
What impact does CVE-2024-28224 have on my system?
CVE-2024-28224 allows unauthorized users to interact with the API, potentially leading to data deletion and denial of service.
Is CVE-2024-28224 exploitable remotely?
Yes, CVE-2024-28224 can be exploited remotely, allowing attackers to misuse the API.
What should I do if I cannot upgrade to version 0.1.29 to mitigate CVE-2024-28224?
If you cannot upgrade, consider implementing network security measures to restrict access until an upgrade can be performed.