PT-2025-51973 · Unknown+1 · Open Ondemand+2
Honza801
·
Published
2025-12-17
·
Updated
2026-02-18
·
CVE-2025-66029
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Open OnDemand versions prior to 4.1
Description
Open OnDemand provides remote web access to supercomputers. The Apache proxy in versions 4.0.8 and earlier allows sensitive headers to be passed to origin servers. This could allow malicious users to create an origin server on a compute node to record these headers when unsuspecting users connect to it. The
OIDCPassClaimsAs setting can be adjusted to none or environment to stop passing headers to the client. For centers with an OIDC provider, the mod auth openidc session cookies can be adjusted using guidance provided in GHSA-2cwp-8g29-9q32.Recommendations
Versions prior to 4.1 should be updated when the 4.1 release is available.
For versions 4.0.x, use
custom location directives in ood portal.yml to unset or edit sensitive headers.
Set OIDCPassClaimsAs to none or environment.
Adjust the mod auth openidc session cookies using guidance provided in GHSA-2cwp-8g29-9q32 for centers with an OIDC provider.Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache
Open Ondemand
Mod Auth Openidc