OSC
OSC Open Ondemand: vulnerabilidades y CVE
OSC Open Ondemand tiene 8 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses5
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-44371 | Media (5.3) | 0.44% | — | 14 may 2026 | Open OnDemand is an open-source high-performance computing portal. Prior to 4.0.11, 4.1.5, and 4.2.2, specially crafted filenames can execute javascript in the file browser This vulnerability is fixed in 4.0.11, 4.1.5,… |
| CVE-2026-26002 | Media (6.3) | 0.67% | — | 4 mar 2026 | Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible to malicious input when navigating to a directory. This has been… |
| CVE-2025-66029 | Alta (7.6) | 0.20% | — | 17 dic 2025 | Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to origin servers. This means malicious users can create an origin server… |
| CVE-2025-64185 | Media (6.9) | 0.29% | — | 20 nov 2025 | Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this… |
| CVE-2025-62724 | Media (4.3) | 0.21% | — | 20 nov 2025 | Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, users can craft a "Time of Check to Time of Use" (TOCTOU) attack when downloading zip files to access files outside of the OOD_ALLOWLIST.… |
| CVE-2025-58435 | Media (4.1) | 0.27% | — | 9 sept 2025 | Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not correctly rotate the password when TurboVNC was higher than version 3.1.2. The likelihood of… |
| CVE-2025-53636 | Media (5.4) | 0.29% | — | 11 jul 2025 | Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many errors. Users who flood logs can create very large log files causing a Denial of Service (DoS) to… |
| CVE-2020-36247 | Alta (8.8) | 0.45% | — | 19 feb 2021 | Open OnDemand before 1.5.7 and 1.6.x before 1.6.22 allows CSRF. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.