Skip to content

Unauthorized API Pull Access Check

api-pull-access-check is a critical severity check in the ai category, written in yaml. Its source is templates/ai/ollama/apipull-access-sending-post.yaml in cert-x-gen-templates.

This template checks for unauthorized access to the /api/pull endpoint. It sends a POST request attempting to trigger a model pull operation and verifies whether the endpoint responds with an initial status output that indicates the pull was accepted or started. Unauthorized access to this endpoint could allow attackers to manipulate or exfiltrate model data, corresponding to the risk described in CVE-2024-37032.

Field Value
Id api-pull-access-check
Severity critical
Language yaml
Category ai
Author CERT-X-GEN Automated Generator
Template version 1.0.0
Confidence 95
CVSS 9.8
Weakness CWE-306
Tags api, unauthorized-access, model-pull, critical, cve-2024-37032, ollama
Target kind not recorded
Oracle not recorded

The file declares cve_ids, http, remediation as well. Those are not tabled above; read the source for what they carry.

Declared in the header. cxg parses @references and then discards it, and nothing at scan time reads it, so this is the only place the links a template cites are surfaced.

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info api-pull-access-check

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.