Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f6mr-38g8-39rg

Опубликовано: 18 дек. 2025
Источник: github
Github: Прошло ревью
CVSS4: 9.3

Описание

Ollama Platform has missing authentication enabling attackers to perform model management operations

A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.

Пакеты

Наименование

github.com/ollama/ollama

go
Затронутые версииВерсия исправления

<= 0.13.5

Отсутствует

EPSS

Процентиль: 46%
0.00232
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-284
CWE-306

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 месяцев назад

A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.

CVSS3: 9.8
debian
около 2 месяцев назад

A critical authentication bypass vulnerability exists in Ollama platfo ...

EPSS

Процентиль: 46%
0.00232
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-284
CWE-306