Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2013-4471

около 12 лет назад

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.

CVSS2: 5.5
EPSS: Низкий
redhat логотип

CVE-2013-4471

почти 13 лет назад

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2013-4471

около 12 лет назад

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.

CVSS2: 5.5
EPSS: Низкий
debian логотип

CVE-2013-4471

около 12 лет назад

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 doe ...

CVSS2: 5.5
EPSS: Низкий
github логотип

GHSA-3hqv-63pg-94p2

около 4 лет назад

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2013-4471

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.

CVSS2: 5.5
1%
Низкий
около 12 лет назад
redhat логотип
CVE-2013-4471

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.

CVSS2: 2.6
1%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-4471

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.

CVSS2: 5.5
1%
Низкий
около 12 лет назад
debian логотип
CVE-2013-4471

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 doe ...

CVSS2: 5.5
1%
Низкий
около 12 лет назад
github логотип
GHSA-3hqv-63pg-94p2

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу