CVE-2025-64185

Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability.
CVSS

No CVSS.

Configurations

No configuration.

History

20 Nov 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-20 17:15

Updated : 2025-11-21 15:13


NVD link : CVE-2025-64185

Mitre link : CVE-2025-64185

CVE.ORG link : CVE-2025-64185


JSON object : View

Products Affected

No product.

CWE
CWE-277

Insecure Inherited Permissions

CWE-552

Files or Directories Accessible to External Parties