CVE Explorer
CVE-2025-66029
Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to origin servers. This means malicious users can create an origin server on a compute node that record these headers when unsuspecting users connect to it. Maintainers anticipate a patch in a 4.1 release. Workarounds exist for 4.0.x versions. Using `custom_location_directives` in `ood_portal.yml` in version 4.0.x (not available for versions below 4.0) c
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-522","description":"CWE-522: Insufficiently Protected Credentials","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6686c96067817f190b12c7ed32e32b7cbeaa6c9cde3951b2359d449d5e87e2dc · sha256:409469a3220e2dc8… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-523","description":"CWE-523: Unprotected Transport of Credentials","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6686c96067817f190b12c7ed32e32b7cbeaa6c9cde3951b2359d449d5e87e2dc · sha256:409469a3220e2dc8… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"ondemand","vendor":"OSC","versions":[{"status":"affected","version":"<= 4.0.8"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6686c96067817f190b12c7ed32e32b7cbeaa6c9cde3951b2359d449d5e87e2dc · sha256:409469a3220e2dc8… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.6,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6686c96067817f190b12c7ed32e32b7cbeaa6c9cde3951b2359d449d5e87e2dc · sha256:409469a3220e2dc8… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-522","description":"CWE-522: Insufficiently Protected Credentials","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6686c96067817f190b12c7ed32e32b7cbeaa6c9cde3951b2359d449d5e87e2dc · sha256:409469a3220e2dc8… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-523","description":"CWE-523: Unprotected Transport of Credentials","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6686c96067817f190b12c7ed32e32b7cbeaa6c9cde3951b2359d449d5e87e2dc · sha256:409469a3220e2dc8… · /containers/cna/problemTypes/1/descriptions/0
Source references
1 source assertion{"name":"https://github.com/OSC/ondemand/security/advisories/GHSA-2cwp-8g29-9q32","tags":["x_refsource_CONFIRM"],"url":"https://github.com/OSC/ondemand/security/advisories/GHSA-2cwp-8g29-9q32"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6686c96067817f190b12c7ed32e32b7cbeaa6c9cde3951b2359d449d5e87e2dc · sha256:409469a3220e2dc8… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.