CVE-2024-39719 is a high-severity file existence disclosure vulnerability affecting Ollama through version 0.3.14. An unauthenticated attacker can remotely exploit this with low complexity by sending a crafted request to the api/create endpoint, which reflects error messages indicating if a file exists on the server. Rated 7.5 CVSS, this allows for significant information gathering, posing a high confidentiality impact. While not on CISA's KEV, exploit code (PoC) has been confirmed to exist on GitHub, and the vulnerability is listed on the Hot List as active, drawing notable community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.3.14CPE matchmatch criteria | cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.