Skip to content

CVE-2013-4471

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0018 (0.2%)
Percentile: 39.3%
EPSS: 2026-05-06

Affects

openstack:horizon

Technical description

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.

Published: 5/14/2014, 7:55:10 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam