Vulnerability Report: GO-2024-3104
- CVE-2024-45436, GHSA-846m-99qv-67mg
- Affects: github.com/ollama/ollama
- Published: Aug 30, 2024
- Modified: Dec 12, 2024
Ollama can extract members of a ZIP archive outside of the parent directory in github.com/ollama/ollama
For detailed information about this vulnerability, visit https://github.com/advisories/GHSA-846m-99qv-67mg.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.1.47
1 unexported affected symbols
- tempZipFiles
-
before v0.1.47
1 unexported affected symbols
- parseFromZipFile
Aliases
References
- https://github.com/advisories/GHSA-846m-99qv-67mg
- https://github.com/ollama/ollama/commit/123a722a6f541e300bc8e34297ac378ebe23f527
- https://github.com/ollama/ollama/pull/5314
- https://github.com/ollama/ollama/compare/v0.1.46...v0.1.47
- https://vuln.go.dev/ID/GO-2024-3104.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.