CVE-2025-66029

Source
https://cve.org/CVERecord?id=CVE-2025-66029
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66029.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-66029
Aliases
  • GHSA-2cwp-8g29-9q32
Published
2025-12-17T22:32:51.982Z
Modified
2026-03-10T14:47:17.183683Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N CVSS Calculator
Summary
Open OnDemand affected by Apache proxy passing sensitive headers
Details

Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to origin servers. This means malicious users can create an origin server on a compute node that record these headers when unsuspecting users connect to it. Maintainers anticipate a patch in a 4.1 release. Workarounds exist for 4.0.x versions. Using custom_location_directives in ood_portal.yml in version 4.0.x (not available for versions below 4.0) centers can unset and or edit these headers. Note that OIDCPassClaimsAs both is the default and centers can set OIDCPassClaimsAs to none or environment to stop passing these headers to the client. Centers that have an OIDC provider with the OIDCPassClaimsAs with none or environment settings can adjust the settings using guidance provided in GHSA-2cwp-8g29-9q32 to unset the modauthopenidc_session cookies.

Database specific
{
    "cwe_ids": [
        "CWE-522",
        "CWE-523"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66029.json"
}
References

Affected packages

Git / github.com/osc/ondemand

Affected ranges

Type
GIT
Repo
https://github.com/osc/ondemand
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.0.8"
        }
    ]
}

Affected versions

v1.*
v1.2.1
v1.3.0
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.3.6
v1.3.7
v1.4.0
v1.4.1
v1.4.10
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.4.9
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6
v1.6.0
v1.6.1
v1.6.10
v1.6.11
v1.6.12
v1.6.12_citest
v1.6.13
v1.6.14
v1.6.15
v1.6.16
v1.6.17
v1.6.17-2
v1.6.18
v1.6.18_rc1
v1.6.18_rc2
v1.6.19
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.6.7
v1.6.8
v1.6.8_cr1
v1.6.8_cr3
v1.6.9
v1.7.0
v1.7.0-2
v1.7.0_rc1
v1.7.0_rc2
v1.7.1
v1.7.10
v1.7.10-2
v1.7.11
v1.7.12
v1.7.14
v1.7.2
v1.7.2_demo
v1.7.2_demo-2
v1.7.3
v1.7.3-2
v1.7.3-3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.7_rc1
v1.7.7_rc2
v1.7.7_rc3
v1.7.7_rc4
v1.7.7_rc5
v1.7.7_rc5-2
v1.7.8
v1.7.9
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.13-2
v1.8.14
v1.8.15
v1.8.16
v1.8.17
v1.8.18
v1.8.19-2
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.*
v2.0.0
v2.0.1
v2.0.10
v2.0.11
v2.0.12
v2.0.13
v2.0.14
v2.0.15
v2.0.16
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
v2.1.0
v2.1.0-0.rc1
v2.1.0-0.rc2
v2.1.0-0.rc3
v2.1.0-0.rc4
v2.1.0-0.rc5
v2.1.0-0.rc6
v2.1.0-0.rc7
v2.1.0-0.rc8
v2.1.0-0.rc9
v2.1.0-0.start
v2.1.0-0.start.1
v2.1.0-0.start.2
v2.1.0-0.start.3
v2.1.0-0.start.4
v3.*
v3.0.0
v3.0.0-0.rc1
v3.0.1
v3.1.0
v3.1.0-0.1.start.1
v3.1.0-0.rc1
v3.1.0-0.rc2
v4.*
v4.0.0
v4.0.0-0.rc1
v4.0.0-0.start.1
v4.0.1
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66029.json"