Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f6mr-38g8-39rg | Ollama Platform has missing authentication enabling attackers to perform model management operations |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 30 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:* |
Fri, 19 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-306 | |
| Metrics |
cvssV3_1
|
Fri, 19 Dec 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ollama
Ollama ollama |
|
| Vendors & Products |
Ollama
Ollama ollama |
Thu, 18 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-19T18:02:03.129Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63389
Updated: 2025-12-19T17:35:52.267Z
Status : Analyzed
Published: 2025-12-18T16:15:54.760
Modified: 2025-12-30T20:00:32.400
Link: CVE-2025-63389
No data.
OpenCVE Enrichment
Updated: 2025-12-19T09:18:08Z
Github GHSA