6.6

CVE-2024-28224

Medienbericht
Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model, or cause a denial of service (resource exhaustion).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ollama ≫ Ollama Version < 0.1.29
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.25
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 6.6 1.8 4.7
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
CWE-346 Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
25.08.2026 17:31
https://www.nccgroup.trust/us/our-research/?research=Technical+advisories
Broken Link
https://github.com/ollama/ollama/releases
Release Notes
https://research.nccgroup.com/2024/04/08/technical-advisory-ollama-dns-rebinding-attack-cve-2024-28224/
Not Applicable