Логотип exploitDog
bind:CVE-2013-4471
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2013-4471

Количество 5

Количество 5

ubuntu логотип

CVE-2013-4471

больше 11 лет назад

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.

CVSS2: 5.5
EPSS: Низкий
redhat логотип

CVE-2013-4471

больше 12 лет назад

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2013-4471

больше 11 лет назад

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.

CVSS2: 5.5
EPSS: Низкий
debian логотип

CVE-2013-4471

больше 11 лет назад

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 doe ...

CVSS2: 5.5
EPSS: Низкий
github логотип

GHSA-3hqv-63pg-94p2

больше 3 лет назад

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2013-4471

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.

CVSS2: 5.5
0%
Низкий
больше 11 лет назад
redhat логотип
CVE-2013-4471

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.

CVSS2: 2.6
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-4471

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.

CVSS2: 5.5
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2013-4471

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 doe ...

CVSS2: 5.5
0%
Низкий
больше 11 лет назад
github логотип
GHSA-3hqv-63pg-94p2

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу