CVE-2013-4471 describes a vulnerability in OpenStack Dashboard (Horizon) before version 2013.2, where the Identity v3 API allowed users to change their password without requiring the current password. This flaw, with a CVSS score of 5.5, enables an authenticated attacker to easily modify a user's password if they possess the user's authentication token, potentially leading to unauthorized account access. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2013.1, < 2013.2CPE matchmatch criteria | cpe:2.3:a:openstack:horizon:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.