yahoo-eng-team team mailing list archive
-
yahoo-eng-team team
-
Mailing list archive
-
Message #06128
[Bug 1237989] Re: user can update his password without knowing the old password
Published on OpenStack and OpenStack-Dev mailing lists on 22 Nov 2013.
** Changed in: ossn
Status: In Progress => Fix Released
--
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to Keystone.
https://bugs.launchpad.net/bugs/1237989
Title:
user can update his password without knowing the old password
Status in OpenStack Dashboard (Horizon):
Fix Released
Status in OpenStack Identity (Keystone):
Fix Released
Status in OpenStack Security Notes:
Fix Released
Bug description:
a user logged into horizon can change his password without needing to
type in the correct old password. It's just required to type in
anything as the old password.
To manage notifications about this bug go to:
https://bugs.launchpad.net/horizon/+bug/1237989/+subscriptions