Ollama 在 端点中存在路径遍历漏洞,原因是 函数对层摘要(layer digest)的验证不充分。未认证的远程攻击者可以将路径遍历序列指定为层摘要,从而导致恶意二进制文件被写入模型存储目录之外。 关键的是,如果服务器进程对 目录具有写权限(大多数 Ollama Docker 映像中的默认配置),攻击者可以将恶意文件写入该目录。在下一次服务器重启时,该文件会被加载并执行,从而导致以 root 权限进行远程代码执行。 此问题已在 0.35.0 版本中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet