VYPR

Open Ondemand

by Osc

Source repositories

CVEs (3)

  • CVE-2020-36247HigFeb 19, 2021
    risk 0.50cvss 8.8epss 0.00

    Open OnDemand before 1.5.7 and 1.6.x before 1.6.22 allows CSRF.

  • CVE-2025-66029HigDec 17, 2025
    risk 0.49cvss 7.6epss 0.00

    Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to origin servers. This means malicious users can create an origin server on a compute node that record these headers when unsuspecting…

  • CVE-2026-26002CriMar 4, 2026
    risk 0.00cvss 9.8epss 0.01

    Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible to malicious input when navigating to a directory. This has been patched in versions 4.0.9 and 4.1.3. Versions below this remain…