An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the CreateModel route with a path parameter that does not exist, it reflects the "File does not exist" error message to the attacker, providing a primitive for file existence on the server.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 01 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Ollama
Ollama ollama
Weaknesses CWE-209
CPEs cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:*
Vendors & Products Ollama
Ollama ollama
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 01 Nov 2024 14:30:00 +0000

Type Values Removed Values Added
References

Fri, 01 Nov 2024 14:00:00 +0000

Type Values Removed Values Added
References

Thu, 31 Oct 2024 19:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the CreateModel route with a path parameter that does not exist, it reflects the "File does not exist" error message to the attacker, providing a primitive for file existence on the server.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-01T15:41:25.167Z

Reserved: 2024-06-28T00:00:00

Link: CVE-2024-39719

cve-icon Vulnrichment

Updated: 2024-11-01T15:41:18.312Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-31T20:15:04.770

Modified: 2025-05-13T13:32:48.047

Link: CVE-2024-39719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses