Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 24 Nov 2025 18:15:00 +0900

Type Values Removed Values Added
First Time appeared Osc
Osc open Ondemand
Vendors & Products Osc
Osc open Ondemand

Sat, 22 Nov 2025 02:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Nov 2025 02:15:00 +0900

Type Values Removed Values Added
Description Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability.
Title Open OnDemand RPM packages create world writable locations
Weaknesses CWE-277
CWE-552
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-21T16:57:10.499Z

Reserved: 2025-10-28T21:07:16.440Z

Link: CVE-2025-64185

cve-icon Vulnrichment

Updated: 2025-11-21T16:57:07.803Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-20T17:15:53.017

Modified: 2025-11-21T15:13:13.800

Link: CVE-2025-64185

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-24T18:09:42Z

Weaknesses