5.5
CVSSv2

CVE-2013-4471

Published: 14/05/2014 Updated: 09/03/2021
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

The Identity v3 API in OpenStack Dashboard (Horizon) prior to 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote malicious users to change a user password by leveraging the authentication token for that user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack horizon

Vendor Advisories

The Identity v3 API in OpenStack Dashboard (Horizon) before 20132 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user ...