Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenStack Dashboard 信任管理问题漏洞
Vulnerability Description
OpenStack是美国国家航空航天局(National Aeronautics and Space Administration)和美国Rackspace公司合作研发的一个云平台管理项目。Dashboard(Horizon)是其中的一个基于Django框架提供开发测试环境的项目。 OpenStack Dashboard 2013.1及之前版本的Identity v3 API中存在安全漏洞,该漏洞源于当更改用户账户密码时没有要求提供当前使用的密码。远程攻击者可借助身份认证令牌利用该漏洞更改用户密码。
CVSS Information
N/A
Vulnerability Type
N/A