CVE-2025-64185 Details
Description
Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability.
A vulnerability exists in Open OnDemand versions prior to 4.0.8 and 3.1.16, where the packages create world writable directories in the GEM_PATH. This could potentially allow unauthorized users to modify or add files in those locations, leading to security risks. The issue has been addressed in versions 4.0.8 and 3.1.16.
Users can upgrade to Open OnDemand versions 4.0.8 or 3.1.16 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 20, 2025CISA-ADP
Assessed Nov 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/OSC/ondemand/security/advisories/GHSA-r2cg-hg78-gq9p | [email protected] | AdvisoryBroken LinkVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-277 | Insecure Inherited Permissions | [email protected] |
| CWE-552 | Files or Directories Accessible to External Parties | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Open OnDemand | < 4.0.8 (semver) < 3.1.16 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 20, 2025 | New CVE Received | [email protected] |
Volerion