Database/AI/ML frameworks & serving
Ollama: Path traversal in the digest field
Impact
Path traversal in the digest field → arbitrary file overwrite → RCE
Who can reach it
Unauthenticated network to the Ollama API (/api/pull from an attacker-controlled registry)
What to do
Upgrade to 0.1.34+. Ollama binds 11434 with no auth by default — never expose to a tenant network
Fleet impact
How widespread
Common - Ollama is the standard single-node LLM server on GPU dev boxes and small inference tenants; Docker installs run the API as root
Cost to remediate
daemon-restart - upgrade to 0.1.34+; trivial on the daemon, but every compromised host is root-owned and needs rebuild
Why it hits the whole fleet
Unvalidated digest in OCI manifests gives path traversal; a rogue registry writes /etc/ld.so.preload and gets unauthenticated RCE as root - a poisoned model pull compromises every node that pulled it
References
Related entries
- Ollama: File-existence disclosure via `api/create`CVE-2024-39719 · OllamaHigh
- Ollama: Path traversal in `api/push` discloses server filesystem layoutCVE-2024-39722 · OllamaHigh
- Ollama: DNS rebinding grants a remote page full API accessCVE-2024-28224 · OllamaMedium
- MLflow (model flavors): Deserialization RCE from a maliciously uploaded model (one of a family: 37052–37060)CVE-2024-37052 · MLflow (model flavors)High
- MLflow (recipes / pyfunc): RCE via a maliciously crafted MLprojectCVE-2024-37061 · MLflow (recipes / pyfunc)High
- ONNX (`download_model_with_test_data`): Arbitrary file overwrite from a crafted model archiveCVE-2024-5187 · ONNX (`download_model_with_test_data`)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.