CVE-2024-28224 Information
Apr 09, 2024
cve
Description
Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API thereby letting an unauthorized user chat with a large language model delete a model or cause a denial of service (resource exhaustion).
Reference
https://www.nccgroup.trust/us/our-research/?research=Technical+advisories https://github.com/ollama/ollama/releases https://research.nccgroup.com/2024/04/08/technical-advisory-ollama-dns-rebinding-attack-cve-2024-28224/
Share on: