Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not correctly rotate the password when TurboVNC was higher than version 3.1.2. The likelihood of exploitation is low as a user would need to share their link to an active desktop session and the other user would need to be authenticated to the portal. But obtaining the link would allow that user to perform any actions as the original user and access their data. Open OnDemand 3.1.15 and 4.0.7 have patched this vulnerability and correctly rotate passwords for any version of TurboVNC. As a workaround, downgrade TurboVNC to a version lower than 3.1.2.
                
            CVSS
                No CVSS.
References
                    Configurations
                    No configuration.
History
                    09 Sep 2025, 20:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-09-09 20:15
Updated : 2025-09-11 17:14
NVD link : CVE-2025-58435
Mitre link : CVE-2025-58435
CVE.ORG link : CVE-2025-58435
JSON object : View
Products Affected
                No product.
CWE
                
                    
                        
                        CWE-262
                        
            Not Using Password Aging
