Open OnDemand
cpe:2.3:a:osc:open_ondemand:*:*:*:*:*:*:*
- < 4.0.8
- < 3.1.16
A vulnerability exists in Open OnDemand versions prior to 4.0.8 and 3.1.16, where the packages create world writable directories in the GEM_PATH. This could potentially allow unauthorized users to modify or add files in those locations, leading to security risks. The issue has been addressed in versions 4.0.8 and 3.1.16.
The world writable GEM_PATH locations could be exploited to introduce malicious code or modify existing files, potentially leading to unauthorized actions within the application or environment.
Users can upgrade to Open OnDemand versions 4.0.8 or 3.1.16 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.