CVE-2024-28224

Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model, or cause a denial of service (resource exhaustion).
Configurations

Configuration 1 (hide)

cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-04-08 19:15

Updated : 2025-05-13 00:42


NVD link : CVE-2024-28224

Mitre link : CVE-2024-28224

CVE.ORG link : CVE-2024-28224


JSON object : View

Products Affected

ollama

  • ollama
CWE
CWE-346

Origin Validation Error