PT-2025-51973 · Unknown+1 · Open Ondemand+2

Honza801

·

Published

2025-12-17

·

Updated

2026-02-18

·

CVE-2025-66029

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Open OnDemand versions prior to 4.1
Description Open OnDemand provides remote web access to supercomputers. The Apache proxy in versions 4.0.8 and earlier allows sensitive headers to be passed to origin servers. This could allow malicious users to create an origin server on a compute node to record these headers when unsuspecting users connect to it. The OIDCPassClaimsAs setting can be adjusted to none or environment to stop passing headers to the client. For centers with an OIDC provider, the mod auth openidc session cookies can be adjusted using guidance provided in GHSA-2cwp-8g29-9q32.
Recommendations Versions prior to 4.1 should be updated when the 4.1 release is available. For versions 4.0.x, use custom location directives in ood portal.yml to unset or edit sensitive headers. Set OIDCPassClaimsAs to none or environment. Adjust the mod auth openidc session cookies using guidance provided in GHSA-2cwp-8g29-9q32 for centers with an OIDC provider.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66029
GHSA-2CWP-8G29-9Q32

Affected Products

Apache
Open Ondemand
Mod Auth Openidc