← Retour à la recherche de CVE

CVE-2026-44371

Open OnDemand

Description

Open OnDemand is an open-source high-performance computing portal. Prior to 4.0.11, 4.1.5, and 4.2.2, specially crafted filenames can execute javascript in the file browser This vulnerability is fixed in 4.0.11, 4.1.5, and 4.2.2.

CVSS 5.3EPSS 0.262%Risque 0.54
Voir la source
Publication
2026-05-14 15:16:48
Versions concernées
<4.0.11, <4.1.5, <4.2.2
Type
Core software
Vecteur
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X