Open OnDemand World Writable GEM_PATH Vulnerability

Vulnerability

A vulnerability exists in Open OnDemand versions prior to 4.0.8 and 3.1.16, where the packages create world writable directories in the GEM_PATH. This could potentially allow unauthorized users to modify or add files in those locations, leading to security risks. The issue has been addressed in versions 4.0.8 and 3.1.16.

Impact

The world writable GEM_PATH locations could be exploited to introduce malicious code or modify existing files, potentially leading to unauthorized actions within the application or environment.

Remediation

Users can upgrade to Open OnDemand versions 4.0.8 or 3.1.16 to address this vulnerability.

Added: Nov 20, 2025, 5:18 PM
Updated: Nov 20, 2025, 5:18 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
0.6
exploitability
7.4
remediation
7.7
relevance
1.1
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.