VulnerabilityModified
CVE-2020-27958
The Job Composer app in Ohio Supercomputer Center Open OnDemand before 1.7.19 and 1.8.x before 1.8.18 allows remote authenticated users to provide crafted input in a job template.
MEDIUM 4.3EPSS 1.05%
Does this matter?
Lower severity and a low EPSS score (1.05%). Track it; it rarely justifies an emergency change on its own.
Description
The Job Composer app in Ohio Supercomputer Center Open OnDemand before 1.7.19 and 1.8.x before 1.8.18 allows remote authenticated users to provide crafted input in a job template.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.05% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-116
- Affected
- osu/ohio supercomputer center open ondemand
- Source
- cve@mitre.org
References
- https://discourse.osc.edu/t/security-fix-in-open-ondemand-1-8-18-and-1-7-19-patch-releases-now-available/1198Release Notes, Vendor Advisory
- https://github.com/OSC/Open-OnDemand/commits/masterRelease Notes, Third Party Advisory
- https://listsprd.osu.edu/pipermail/ood-users/Broken Link, Vendor Advisory
- https://discourse.osc.edu/t/security-fix-in-open-ondemand-1-8-18-and-1-7-19-patch-releases-now-available/1198Release Notes, Vendor Advisory
- https://github.com/OSC/Open-OnDemand/commits/masterRelease Notes, Third Party Advisory
- https://listsprd.osu.edu/pipermail/ood-users/Broken Link, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.