CVE-2024-37032: stato di sfruttamento e disponibilità della patch
CVE-2024-37032 · CVSS 8.8 HIGH · EPSS 90%
Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the TestGetBlobsPath test cases such as fewer than 64 hex digits, more than 64 hex digits, or an initial ../ substring.
CVE-2024-37032 viene sfruttato?
Non è nel catalogo CISA KEV.
EPSS stima la probabilità di sfruttamento nei prossimi 30 giorni al 90%.
Codice di exploit pubblico: integrato in uno strumento pubblico.
Esistono regole di detection pubbliche.
Quali prodotti e versioni sono interessati?
Nessun elenco di pacchetti interessati registrato qui.