CVE-2025-58435CWE-262

Open OnDemand didn't rotate password for VNC batch_connect

Medium · published September 9, 2025

CVSS v4.0
4.1
EPSS
0%
Percentile
18.0
In the wild
Unconfirmed
What it is

Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not correctly rotate the password when TurboVNC was higher than version 3.1.2. The likelihood of exploitation is low as a user would need to share their link to an active desktop session and the other user would need to be authenticated to the portal. But obtaining the link would allow that user to perform any actions as the original user and access their data. Open OnDemand 3.1.15 and 4.0.7 have patched this vulnerability and correctly rotate passwords for any version of TurboVNC. As a workaround, downgrade TurboVNC to a version lower than 3.1.2.

The record
Technical detail
CVSS v4.0
4.1 · MEDIUM
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U
EPSS
0.00264 · 18.0th percentile
Weakness
CWE-262 · Not Using Password Aging
Published
2025-09-09T19:43Z
EPSS history
Timeline
  • 09 SEP 19:43Z
    Open OnDemand didn't rotate password for VNC batch_connect
    cvelistv5