CVE-2026-26002
- EPSS 0.06%
- Veröffentlicht 04.03.2026 22:05:28
- Zuletzt bearbeitet 18.03.2026 16:09:26
Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible to malicious input when navigating to a directory. This has been patched in versions 4.0.9 and 4.1.3...
CVE-2025-66029
- EPSS 0.05%
- Veröffentlicht 17.12.2025 22:32:51
- Zuletzt bearbeitet 18.02.2026 19:42:12
Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to origin servers. This means malicious users can create an origin server on a compute node that record th...
CVE-2025-64185
- EPSS 0.08%
- Veröffentlicht 20.11.2025 16:58:01
- Zuletzt bearbeitet 15.04.2026 00:35:42
Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability.
CVE-2025-62724
- EPSS 0.04%
- Veröffentlicht 20.11.2025 16:53:13
- Zuletzt bearbeitet 15.04.2026 00:35:42
Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, users can craft a "Time of Check to Time of Use" (TOCTOU) attack when downloading zip files to access files outside of the OOD_ALLOWLIST. This vulnerability impacts sites...
CVE-2025-58435
- EPSS 0.06%
- Veröffentlicht 09.09.2025 19:43:47
- Zuletzt bearbeitet 15.04.2026 00:35:42
Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not correctly rotate the password when TurboVNC was higher than version 3.1.2. The likelihood of exploitation is low as a user would ne...
CVE-2025-53636
- EPSS 0.09%
- Veröffentlicht 11.07.2025 21:20:14
- Zuletzt bearbeitet 15.04.2026 00:35:42
Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many errors. Users who flood logs can create very large log files causing a Denial of Service (DoS) to the ondemand system. This vulnera...
CVE-2020-36247
- EPSS 0.16%
- Veröffentlicht 19.02.2021 06:15:12
- Zuletzt bearbeitet 21.11.2024 05:29:09
Open OnDemand before 1.5.7 and 1.6.x before 1.6.22 allows CSRF.