RULE(RULE ID:338725)

Rule General Information
Release Date: 2025-03-06
Rule Name: Ollama 0.1.45 Push Api File Disclosure Vulnerability (CVE-2024-39722)
Severity:
CVE ID:
Rule Protection Details
Description: Ollama is an open-source large language model (LLM) runtime environment and toolkit designed to help developers easily deploy, manage, and use models (such as DeepSeek). Versions prior to Ollama 0.1.46 had a security vulnerability originating from a path traversal issue in the api/push route, which could expose files on the deployment server
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.