Skip to main content

Insecure Inherited Permissions

CVE-2025-64185

Severity Medium
Score 6.9/10

Summary

Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability.

  • LOW
  • NETWORK
  • NONE
  • NONE

CWE-277 - Insecure Inherited Permissions

A product defines a set of insecure permissions that are inherited by objects that are created by the program.

References

Advisory Timeline

  • Published