Open OnDemand
cpe:2.3:a:osc:open_ondemand:*:*:*:*:*:*:*
- <= 4.0.7
- <= 3.1.15
A vulnerability in Open OnDemand, an open-source HPC portal, prior to versions 4.0.8 and 3.1.16, allows users to perform a 'Time of Check to Time of Use' (TOCTOU) attack when downloading zip files. This exploitation can lead to accessing files outside of the designated allowlist. The issue affects sites utilizing the file browser allowlists in all current Open OnDemand versions, although accessed files remain protected by UNIX permissions.
Exploitation of this vulnerability could lead to unauthorized access of files outside the user's allowlist, although such files would still be subject to UNIX permission restrictions.
Users can upgrade to Open OnDemand versions 4.0.8 or 3.1.16, both of which have been patched for this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.