Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible to malicious input when navigating to a directory. This has been patched in versions 4.0.9 and 4.1.3.
Versions below this remain susceptible.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 3
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Osc Open_Ondemand
cpe:2.3:a:osc:open_ondemand:*:*:*:*:*:*:*:*
|
— |
3.1.16
|
|
Osc Open_Ondemand
cpe:2.3:a:osc:open_ondemand:*:*:*:*:*:*:*:*
|
4.0.0
|
4.0.9
|
|
Osc Open_Ondemand
cpe:2.3:a:osc:open_ondemand:*:*:*:*:*:*:*:*
|
4.1.0
|
4.1.3
|