Password Rotation Issue in Open OnDemand HPC Portal by OSC
CVE-2025-58435
4.1MEDIUM
What is CVE-2025-58435?
The Open OnDemand HPC portal has a vulnerability where the password for noVNC interactive applications is not correctly rotated when using TurboVNC versions higher than 3.1.2. If exploited, this could allow an authenticated user who shared their active session link to perform actions as the original user, compromising sensitive data. Users are advised to update to Open OnDemand versions 3.1.15 or 4.0.7 for a fix or alternatively downgrade TurboVNC to below version 3.1.2.
Affected Version(s)
ondemand < 3.1.15 < 3.1.15
ondemand >= 4.0.0-0.rc1, < 4.0.7 < 4.0.0-0.rc1, 4.0.7