CVE-2025-66029 affects Open OnDemand versions 4.0.8 and prior, where the Apache proxy improperly passes sensitive headers to origin servers. This allows a malicious user to set up an origin server on a compute node to record these headers from unsuspecting users. The vulnerability has a CVSS score of 7.6 (HIGH), indicating a network-based attack with low privileges, requiring user interaction, and resulting in high confidentiality impact. While a patch is anticipated in version 4.1, workarounds exist for 4.0.x versions. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.0.8CPE matchmatch criteria | cpe:2.3:a:osc:open_ondemand:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.