Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the TestGetBlobsPath test cases such as fewer than 64 hex digits, more than 64 hex digits, or an initial ../ substring.
Metrics
Affected Vendors & Products
References
History
Thu, 01 May 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ollama
Ollama ollama |
|
CPEs | cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:* | |
Vendors & Products |
Ollama
Ollama ollama |
Thu, 27 Mar 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-22 | |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-05-31T00:00:00.000Z
Updated: 2025-03-27T20:57:59.559Z
Reserved: 2024-05-31T00:00:00.000Z
Link: CVE-2024-37032

Updated: 2024-08-02T03:43:50.887Z

Status : Analyzed
Published: 2024-05-31T04:15:09.617
Modified: 2025-05-01T14:01:44.767
Link: CVE-2024-37032

No data.