PT-2022-8879 · Ohio Supercomputer Center · Open Ondemand
Radoslav Bodó
·
Published
2022-02-26
·
Updated
2022-07-12
·
CVE-2020-27958
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ohio Supercomputer Center Open OnDemand versions 1.7.19 and earlier
Ohio Supercomputer Center Open OnDemand versions 1.8.x through 1.8.17
Description
The Job Composer app allows remote authenticated users to provide crafted input in a job template.
Recommendations
For versions 1.7.19 and earlier, update to version 1.7.19 or later.
For versions 1.8.x through 1.8.17, update to version 1.8.18 or later.
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open Ondemand