[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-6480Date: (C)2014-01-10   (M)2023-12-22


Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.1
Exploit Score: 3.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
http://www.securityfocus.com/archive/1/530624/100/0/threaded
BID-64617
http://libcloud.apache.org/security.html
https://digitalocean.com/blog_posts/transparency-regarding-data-security
https://github.com/fog/fog/issues/2525
openSUSE-SU-2014:0198

CPE    5
cpe:/a:apache:libcloud:0.12.4
cpe:/a:apache:libcloud:0.13.2
cpe:/a:apache:libcloud:0.12.3
cpe:/a:apache:libcloud:0.13.1
...
CWE    1
CWE-200
OVAL    3
oval:org.secpod.oval:def:106249
oval:org.secpod.oval:def:106248
oval:org.secpod.oval:def:106314

© SecPod Technologies