Path Traversal Vulnerability in Ollama's api/push Route
CVE-2024-39722
7.5HIGH
What is CVE-2024-39722?
A path traversal vulnerability has been identified in the Ollama web application that allows attackers to access sensitive files on the server. This issue arises from improper validation of file paths in the api/push route, making it possible for unauthorized users to exploit this weakness. By leveraging this vulnerability, attackers can potentially retrieve files that should not be exposed, leading to data leakage and increased risk for organizations using affected versions of the software.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
54% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
