Bug 1023586 (CVE-2013-4471) - CVE-2013-4471 OpenStack: python-django-horizonpassword reset vulnerability
Summary: CVE-2013-4471 OpenStack: python-django-horizonpassword reset vulnerability
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2013-4471
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1016647 1037414 1037415
Blocks: 1034568
TreeView+ depends on / blocked
 
Reported: 2013-10-25 20:33 UTC by Kurt Seifried
Modified: 2019-09-29 13:09 UTC (History)
21 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2014-03-10 04:36:31 UTC
Embargoed:


Attachments (Terms of Use)

Description Kurt Seifried 2013-10-25 20:33:57 UTC
Rami Vaknin of Red Hat reports:

Version
=======
rhos 4.0 on rhel 6.5, puddle 2013-10-03.3

Description
===========

Scenario:

1. Login to horizon, you can choose any user, either admin or non-admin
2. Click on the Setting link on the right-up corner
3. Choose the Change Password vertical-tab
4. Enter a wrong "Current Password" value
5. Enter a new password in the New Password and New Password Confirm bixes

The password will be changed to the new one althought the old password is wrong.

Note that you're requested to provide a non-empty value in the Current Password box in order to proceed with the change password operation.

Comment 1 Matthias Runge 2013-10-28 07:34:04 UTC
Yes, that's a known issue in a pre-release. It's already fixed in all python-django-horizon-2013.2-1 builds (and later).

Comment 3 Kurt Seifried 2013-12-03 06:20:54 UTC
Upstream reference:

https://bugs.launchpad.net/horizon/+bug/1237989


Note You need to log in before you can comment on or make changes to this bug.