Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Ollama 0.30.0 through 0.33.2 SSRF via Cross-Host Tensor Blob Redirect
Vulnerability Description
Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An attacker can control a registry, serve a malicious tensor-layer manifest, and cause the server to issue GET requests to internal hosts including cloud metadata endpoints.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Ollama 服务端请求伪造漏洞
Vulnerability Description
Ollama是Ollama公司开源的一个可以在本地设备上运行、管理和自定义大语言模型的工具。 Ollama 0.30.0版本至0.33.2版本存在服务端请求伪造漏洞,该漏洞源于在拉取tensor-layer模型时未能验证重定向目标,可能导致未经身份验证的攻击者控制registry并服务恶意tensor-layer manifest,将blob下载重定向到任意主机,进而使服务器向包括云元数据端点在内的内部主机发起GET请求,造成信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A