Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 20 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Description Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability.
Title Open OnDemand RPM packages create world writable locations
Weaknesses CWE-277
CWE-552
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-20T16:58:01.527Z

Reserved: 2025-10-28T21:07:16.440Z

Link: CVE-2025-64185

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-20T17:15:53.017

Modified: 2025-11-20T17:15:53.017

Link: CVE-2025-64185

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.