Back to Database
Status published
Medium
CVE-2025-64185
Open OnDemand RPM packages create world writable locations
Vulnerability Description
Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-64185
Credits & Attribution
No credits recorded in the NVD database.
More from OSC
View All →CVE-2025-66029
Open OnDemand affected by Apache proxy passing sensitive headers
High
7.6
CVE-2025-62724
Open OnDemand allowlist bypass using symlinks in directory downloads (TOCTOU)
Medium
4.3
CVE-2025-58435
Open OnDemand didn't rotate password for VNC batch_connect
Medium
4.1
CVE-2025-53636
Open OnDemand Shell App closed websocket DoS
Medium
5.4
Affected Vendor
Affected Software
ondemand
Vulnerable Versions:
< 4.0.8, < 3.1.16
Timeline
Official Publish:
November 20th, 2025
Last Modified:
November 21st, 2025
Added to House:
July 22nd, 2026