Denial of Service Vulnerability in Open OnDemand by OSC
CVE-2025-53636

5.4MEDIUM

Key Information:

Vendor

Osc

Status
Vendor
CVE Published:
11 July 2025

What is CVE-2025-53636?

Open OnDemand, an open-source high-performance computing (HPC) portal, has a vulnerability that allows users to flood logs by excessively interacting with the shell app. This can lead to the creation of very large log files, resulting in a Denial of Service (DoS) and rendering the system unusable. The vulnerability has been addressed in versions 3.1.14 and 4.0.6.

Affected Version(s)

ondemand >= 1.6, < 3.1.14 < 1.6, 3.1.14

ondemand >= 4.0.0-0.rc1, < 4.0.6 < 4.0.0-0.rc1, 4.0.6

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53636 : Denial of Service Vulnerability in Open OnDemand by OSC