PT-2014-3136 · Apache · Libcloud

Sneako

·

Published

2014-01-07

·

Updated

2022-05-14

·

CVE-2013-6480

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Libcloud versions 0.12.3 through 0.13.2
Description The issue allows local users to obtain sensitive information by leveraging a new VM, due to the scrub data parameter not being set for the destroy DigitalOcean API.
Recommendations For Libcloud versions 0.12.3 through 0.13.2, as a temporary workaround, consider setting the scrub data parameter manually when using the destroy DigitalOcean API until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-6480
GHSA-G892-9H8M-R69R
PYSEC-2014-97

Affected Products

Libcloud