Apache Proxy Vulnerability in Open OnDemand Affecting Remote Access
CVE-2025-66029
7.6HIGH
What is CVE-2025-66029?
The Apache proxy in Open OnDemand versions 4.0.8 and earlier allows the inadvertent passing of sensitive headers to origin servers, potentially enabling malicious users to set up an origin server on compute nodes. When unsuspecting users connect, these headers can be recorded. A patch is anticipated in the upcoming 4.1 release. Users of version 4.0.x can utilize the custom_location_directives in ood_portal.yml to manage these headers, while those with OIDC providers can adjust the OIDCPassClaimsAs settings to enhance security. For comprehensive guidance on mitigating these vulnerabilities, further details are available in the advisory.
Affected Version(s)
ondemand <= 4.0.8
