Vulnerabilities (CVE)

Filtered by vendor Osc
Filtered by product Open Ondemand
Angry Yack Logo
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-66029 1 Osc 1 Open Ondemand 2026-02-18 N/A 7.6 HIGH
Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to origin servers. This means malicious users can create an origin server on a compute node that record these headers when unsuspecting users connect to it. Maintainers anticipate a patch in a 4.1 release. Workarounds exist for 4.0.x versions. Using `custom_location_directives` in `ood_portal.yml` in version 4.0.x (not available for versions below 4.0) c ...

Show More

CVE-2020-36247 1 Osc 1 Open Ondemand 2024-11-21 6.8 MEDIUM 8.8 HIGH
Open OnDemand before 1.5.7 and 1.6.x before 1.6.22 allows CSRF.