Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Open OnDemand didn't rotate password for VNC batch_connect
Vulnerability Description
Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not correctly rotate the password when TurboVNC was higher than version 3.1.2. The likelihood of exploitation is low as a user would need to share their link to an active desktop session and the other user would need to be authenticated to the portal. But obtaining the link would allow that user to perform any actions as the original user and access their data. Open OnDemand 3.1.15 and 4.0.7 have patched this vulnerability and correctly rotate passwords for any version of TurboVNC. As a workaround, downgrade TurboVNC to a version lower than 3.1.2.
CVSS Information
N/A
Vulnerability Type
未使用口令老化机制
Vulnerability Title
Open OnDemand 安全漏洞
Vulnerability Description
Open OnDemand是Ohio Supercomputer Center开源的一个通过Web实现开放式交互式HPC的软件。 Open OnDemand 3.1.15和4.0.7之前版本存在安全漏洞,该漏洞源于密码轮换不当,可能导致会话劫持。
CVSS Information
N/A
Vulnerability Type
N/A