Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model, or cause a denial of service (resource exhaustion).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ollama 安全漏洞
Vulnerability Description
Ollama是Ollama开源的一个可以在本地启动并运行的大型语言模型。 Ollama 0.1.29之前版本存在安全漏洞,该漏洞源于存在DNS重新绑定漏洞,可能会无意中允许远程访问完整的API,从而让未经授权的用户与大语言模型聊天、删除模型或导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A