← Voltar à pesquisa de CVEs

CVE-2026-44371

Open OnDemand

Descrição

Open OnDemand is an open-source high-performance computing portal. Prior to 4.0.11, 4.1.5, and 4.2.2, specially crafted filenames can execute javascript in the file browser This vulnerability is fixed in 4.0.11, 4.1.5, and 4.2.2.

CVSS 5.3EPSS 0.262%Risco 0.54
Ver fonte
Publicação
2026-05-14 15:16:48
Versões afetadas
<4.0.11, <4.1.5, <4.2.2
Tipo
Core software
Vetor
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X