CVE 4.1 MEDIUM

Open OnDemand didn’t rotate password for VNC batch_connect_CVE-2025-58435

4.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U

Description

Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not correctly rotate the password when TurboVNC was higher than version 3.1.2. The likelihood of exploitation is low as a user would need to share their link to an active desktop session and the other user would need to be authenticated to the portal. But obtaining the link would allow that user to perform any actions as the original user and access their data. Open OnDemand 3.1.15 and 4.0.7 have patched this vulnerability and correctly rotate passwords for any version of TurboVNC. As a workaround, downgrade TurboVNC to a version lower than 3.1.2.

Basic Information

ID CVE-2025-58435
Source GitHub_M
Published Sep 9, 2025 at 19:43

Affected Product

Vendor OSC
Product ondemand
Version < 3.1.15
Affected Versions OSC ondemand < 3.1.15
OSC ondemand >= 4.0.0-0.rc1, < 4.0.7

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.