RULE(RULE ID:338728)

Rule General Information
Release Date: 2025-03-06
Rule Name: Ollama 0.1.33 Directory Traversal Vulnerability (CVE-2024-37032)
Severity:
CVE ID:
Rule Protection Details
Description: Ollama is an open-source AI model project that facilitates packaging and accelerates the deployment process of AI models. On June 24, 2024, the CVE-2024-37032 vulnerability in Ollama, which allows directory traversal leading to code execution, was disclosed on the internet. Since Ollama typically lacks authentication and authorization, attackers can exploit the relevant APIs in conjunction with the directory traversal vulnerability to achieve remote code execution and take control of the server. The official release of version 0.1.34 has addressed this vulnerability, and it is recommended to upgrade to version 0.1.34 or higher.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.