« Volver al listado

OSC

OSC Open Ondemand: vulnerabilidades y CVE

OSC Open Ondemand tiene 8 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses5
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-44371Media (5.3)0.44%—14 may 2026
Open OnDemand is an open-source high-performance computing portal. Prior to 4.0.11, 4.1.5, and 4.2.2, specially crafted filenames can execute javascript in the file browser This vulnerability is fixed in 4.0.11, 4.1.5,…
CVE-2026-26002Media (6.3)0.67%—4 mar 2026
Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible to malicious input when navigating to a directory. This has been…
CVE-2025-66029Alta (7.6)0.20%—17 dic 2025
Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to origin servers. This means malicious users can create an origin server…
CVE-2025-64185Media (6.9)0.29%—20 nov 2025
Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this…
CVE-2025-62724Media (4.3)0.21%—20 nov 2025
Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, users can craft a "Time of Check to Time of Use" (TOCTOU) attack when downloading zip files to access files outside of the OOD_ALLOWLIST.…
CVE-2025-58435Media (4.1)0.27%—9 sept 2025
Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not correctly rotate the password when TurboVNC was higher than version 3.1.2. The likelihood of…
CVE-2025-53636Media (5.4)0.29%—11 jul 2025
Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many errors. Users who flood logs can create very large log files causing a Denial of Service (DoS) to…
CVE-2020-36247Alta (8.8)0.45%—19 feb 2021
Open OnDemand before 1.5.7 and 1.6.x before 1.6.22 allows CSRF.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution1
  2. T1552 Unsecured Credentials1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.