Filtered by vendor Osc
Subscribe
Total
2 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-66029 | 1 Osc | 1 Open Ondemand | 2026-02-18 | N/A | 7.6 HIGH |
|
Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to origin servers. This means malicious users can create an origin server on a compute node that record these headers when unsuspecting users connect to it. Maintainers anticipate a patch in a 4.1 release. Workarounds exist for 4.0.x versions. Using `custom_location_directives` in `ood_portal.yml` in version 4.0.x (not available for versions below 4.0) c ...
Show More |
|||||
| CVE-2020-36247 | 1 Osc | 1 Open Ondemand | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
Open OnDemand before 1.5.7 and 1.6.x before 1.6.22 allows CSRF.
|
|||||