Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mvx2-276h-w78v

Опубликовано: 31 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until completion. The req.Path parameter is user-controlled and can be set to /dev/random, which is blocking, causing the goroutine to run infinitely (even after the HTTP request is aborted by the client).

An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until completion. The req.Path parameter is user-controlled and can be set to /dev/random, which is blocking, causing the goroutine to run infinitely (even after the HTTP request is aborted by the client).

EPSS

Процентиль: 37%
0.0016
Низкий

7.5 High

CVSS3

Дефекты

CWE-404

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until completion. The req.Path parameter is user-controlled and can be set to /dev/random, which is blocking, causing the goroutine to run infinitely (even after the HTTP request is aborted by the client).

CVSS3: 7.5
debian
больше 1 года назад

An issue was discovered in Ollama before 0.1.34. The CreateModelHandle ...

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость системы запуска и управления большими языковыми моделями (LLM) Ollama, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 37%
0.0016
Низкий

7.5 High

CVSS3

Дефекты

CWE-404