CVE-2013-4471

Source
https://nvd.nist.gov/vuln/detail/CVE-2013-4471
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2013-4471.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2013-4471
Downstream
Published
2014-05-14T19:55:10Z
Modified
2025-08-09T20:01:26Z
Summary
[none]
Details

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.

References

Affected packages