Skip to content

Conversation

@Ankush-Pathak
Copy link

Updates

  • Affected products

Comments
According to https://gist.github.com/Cristliu/48dae561696374744d9fced07a544ecd, Affected Versions: <= v0.12.3

@github-actions github-actions bot changed the base branch from main to Ankush-Pathak/advisory-improvement-6571 December 22, 2025 05:59
@JonathanLEvans
Copy link

Hi @Ankush-Pathak,

My understanding is that Ollama is not patched yet so the current range is accurate. Do you have a link showing that 0.12.4 is fixed?

@Ankush-Pathak
Copy link
Author

It says in the description of the CVE, A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3 and see Affected Versions: <= v0.12.3 here

@Ankush-Pathak
Copy link
Author

Oh I see what you're saying. I don't find any indication of a fix in the changelog for 0.12.4.
The description of the CVE must then be updated to not mention the version to avoid confusion.

@JonathanLEvans
Copy link

GitHub did not assign the CVE so we cannot make changes to it. If you want, you can contact MITRE about changing the description.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants