CVE-2025-66029
7.6OSC · Open OnDemand
Open OnDemand versions 4.0.8 and prior contain an Apache proxy misconfiguration that allows sensitive headers to be intercepted by malicious users on compute nodes.
Executive summary
A critical vulnerability in Open OnDemand allows attackers to intercept sensitive authentication headers, posing a severe risk to user credentials and session security.
Vulnerability
This vulnerability involves the insecure handling of sensitive headers by the Apache proxy, which permits authenticated users to capture credentials when unsuspecting victims connect to a malicious origin server. The attack requires the attacker to be an authenticated user within the environment.
Business impact
The exposure of sensitive authentication headers can lead to full account takeover or unauthorized access to high performance computing resources. Given the CVSS score of 7.6, this represents a high risk to organizational data integrity and system security. If exploited, an attacker could impersonate legitimate researchers or administrators, resulting in significant unauthorized data access and potential disruption of research operations.
Remediation
Immediate Action: Administrators should review the guidance provided in GHSA-2cwp-8g29-9q32 to apply necessary configuration changes, such as setting OIDCPassClaimsAs to none or environment, and utilizing custom_location_directives to unset sensitive headers.
Proactive Monitoring: Security teams should monitor access logs for unusual patterns related to origin server connections or unexpected header transmission attempts.
Compensating Controls: Implement strict network segmentation for compute nodes and enforce multi-factor authentication where possible to limit the impact of intercepted session tokens.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The risk associated with this vulnerability is significant, as it facilitates the theft of credentials required for accessing sensitive supercomputing environments. Administrators are urged to prioritize the implementation of the provided configuration workarounds immediately, as no official patch is currently available. Regular auditing of proxy configurations is essential until the vendor releases a hardened version.
History
- Disclosed CVE record published
- Published in the daily brief high section
- Analyst report written