← back
CVE-2024-37032highobserved exploitationCWE-22

CVE-2024-37032

100Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 8.8epss 90%
from disclosure to weapon718 days
Published on NVDMay 31
1st PoC+718d
metasploitMay 5
VulnCheck+83d
exploitation probability
90%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the TestGetBlobsPath test cases such as fewer than 64 hex digits, more than 64 hex digits, or an initial ../ substring.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.