Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-63389

Опубликовано: 18 дек. 2025
Источник: debian

Описание

A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ollamaitppackage

Связанные уязвимости

CVSS3: 9.8
nvd
9 месяцев назад

A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.

github
9 месяцев назад

Ollama Platform has missing authentication enabling attackers to perform model management operations