Password Rotation Issue in Open OnDemand HPC Portal by OSC
CVE-2025-58435

4.1MEDIUM

Key Information:

Vendor

Osc

Status
Vendor
CVE Published:
9 September 2025

What is CVE-2025-58435?

The Open OnDemand HPC portal has a vulnerability where the password for noVNC interactive applications is not correctly rotated when using TurboVNC versions higher than 3.1.2. If exploited, this could allow an authenticated user who shared their active session link to perform actions as the original user, compromising sensitive data. Users are advised to update to Open OnDemand versions 3.1.15 or 4.0.7 for a fix or alternatively downgrade TurboVNC to below version 3.1.2.

Affected Version(s)

ondemand < 3.1.15 < 3.1.15

ondemand >= 4.0.0-0.rc1, < 4.0.7 < 4.0.0-0.rc1, 4.0.7

References

CVSS V4

Score:
4.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-58435 : Password Rotation Issue in Open OnDemand HPC Portal by OSC