CVE-2025-66029
- EPSS 0.05%
- Veröffentlicht 17.12.2025 22:32:51
- Zuletzt bearbeitet 18.02.2026 19:42:12
Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to origin servers. This means malicious users can create an origin server on a compute node that record th...
CVE-2025-64185
- EPSS 0.06%
- Veröffentlicht 20.11.2025 16:58:01
- Zuletzt bearbeitet 21.11.2025 15:13:13
Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability.
CVE-2025-62724
- EPSS 0.04%
- Veröffentlicht 20.11.2025 16:53:13
- Zuletzt bearbeitet 21.11.2025 15:13:13
Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, users can craft a "Time of Check to Time of Use" (TOCTOU) attack when downloading zip files to access files outside of the OOD_ALLOWLIST. This vulnerability impacts sites...
CVE-2025-58435
- EPSS 0.06%
- Veröffentlicht 09.09.2025 19:43:47
- Zuletzt bearbeitet 11.09.2025 17:14:25
Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not correctly rotate the password when TurboVNC was higher than version 3.1.2. The likelihood of exploitation is low as a user would ne...
CVE-2025-53636
- EPSS 0.09%
- Veröffentlicht 11.07.2025 21:20:14
- Zuletzt bearbeitet 15.07.2025 13:14:49
Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many errors. Users who flood logs can create very large log files causing a Denial of Service (DoS) to the ondemand system. This vulnera...
CVE-2020-36247
- EPSS 0.16%
- Veröffentlicht 19.02.2021 06:15:12
- Zuletzt bearbeitet 21.11.2024 05:29:09
Open OnDemand before 1.5.7 and 1.6.x before 1.6.22 allows CSRF.