PT-2025-36938 · Unknown+1 · Open Ondemand+1
Andyuea
·
Published
2025-09-09
·
Updated
2025-09-09
·
CVE-2025-58435
CVSS v4.0
4.1
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U |
Name of the Vulnerable Software and Affected Versions:
Open OnDemand versions prior to 3.1.15
Open OnDemand versions prior to 4.0.7
Description:
Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not correctly rotate the password when TurboVNC was higher than version 3.1.2. Exploitation requires a user to share their link to an active desktop session, and the attacker must be authenticated to the portal. Successful exploitation would allow an attacker to perform actions as the original user and access their data.
Recommendations:
Update to Open OnDemand version 3.1.15 or later.
Update to Open OnDemand version 4.0.7 or later.
As a workaround, downgrade TurboVNC to a version lower than 3.1.2.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open Ondemand
Turbovnc