Ollama DNS rebinding vulnerability
High severity
GitHub Reviewed
Published
Apr 8, 2024
to the GitHub Advisory Database
•
Updated Jun 10, 2024
Description
Published by the National Vulnerability Database
Apr 8, 2024
Published to the GitHub Advisory Database
Apr 8, 2024
Reviewed
Apr 8, 2024
Last updated
Jun 10, 2024
Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model, or cause a denial of service (resource exhaustion).
References