Home
MEDIUM: 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N < 4.0.11
affected
>= 4.1.0, < 4.1.5
affected
>= 4.2.0, < 4.2.2
affected
Description
Open OnDemand is an open-source high-performance computing portal. Prior to 4.0.11, 4.1.5, and 4.2.2, specially crafted filenames can execute javascript in the file browser This vulnerability is fixed in 4.0.11, 4.1.5, and 4.2.2.
Problem types
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
>= 4.1.0, < 4.1.5
>= 4.2.0, < 4.2.2
References
github.com/...demand/security/advisories/GHSA-xcv4-m435-m33h