CVE-2013-4183
published 2013-09-16CVE-2013-4183: The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which…
PriorityP45low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.41%
33.2th percentile
The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cinder | < cinder 2013.1.2-4 (bookworm) | cinder 2013.1.2-4 (bookworm) |
| openstack | cinder | — | — |
| openstack | cinder | — | — |
| openstack | cinder | >= 0 < 2013.1.2-4 | 2013.1.2-4 |
| openstack | cinder | >= 0 < 2013.1.2-4 | 2013.1.2-4 |
| openstack | cinder | >= 0 < 2013.1.2-4 | 2013.1.2-4 |
| openstack | cinder | >= 0 < 2013.1.2-4 | 2013.1.2-4 |
| openstack | cinder | >= 0 < 7.0.0a0 | 7.0.0a0 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_ubuntu4.3MEDIUM
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Cinder LVMVolumeDriver does not zero deleted snapshots
osv·2022-05-17
CVE-2013-4183 [MEDIUM] OpenStack Cinder LVMVolumeDriver does not zero deleted snapshots
OpenStack Cinder LVMVolumeDriver does not zero deleted snapshots
The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors.
GHSA
OpenStack Cinder LVMVolumeDriver does not zero deleted snapshots
ghsa·2022-05-17
CVE-2013-4183 [MEDIUM] CWE-200 OpenStack Cinder LVMVolumeDriver does not zero deleted snapshots
OpenStack Cinder LVMVolumeDriver does not zero deleted snapshots
The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors.
OSV
CVE-2013-4183: The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013
osv·2013-09-16·CVSS 2.1
CVE-2013-4183 [LOW] CVE-2013-4183: The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013
The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors.
Ubuntu
Cinder vulnerabilities
vendor_ubuntu·2013-10-23·CVSS 4.3
CVE-2013-4183 [MEDIUM] Cinder vulnerabilities
Title: Cinder vulnerabilities
Summary: Cinder could be made to crash or expose sensitive information.
Rongze Zhu discovered that the Cinder LVM driver did not zero out data
when deleting snapshots. This could expose sensitive information to
authenticated users when subsequent servers use the volume. (CVE-2013-4183)
Grant Murphy discovered that Cinder would allow XML entity processing. A
remote unauthenticated attacker could exploit this using the Cinder API to
cause a denial of service via resource exhaustion. (CVE-2013-4179,
CVE-2013-4202)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
OpenStack: Cinder LVM volume driver does not support secure deletion
vendor_redhat·2013-07-05·CVSS 2.1
CVE-2013-4183 [LOW] OpenStack: Cinder LVM volume driver does not support secure deletion
OpenStack: Cinder LVM volume driver does not support secure deletion
The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors.
Package: openstack-cinder (Red Hat OpenStack Platform 4) - Affected
Debian
CVE-2013-4183: cinder - The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1...
vendor_debian·2013·CVSS 2.1
CVE-2013-4183 [LOW] CVE-2013-4183: cinder - The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1...
The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2013.1.2-4)
bullseye: resolved (fixed in 2013.1.2-4)
forky: resolved (fixed in 2013.1.2-4)
sid: resolved (fixed in 2013.1.2-4)
trixie: resolved (fixed in 2013.1.2-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4183 openstack-cinder: OpenStack: Cinder LVM volume driver does not support secure deletion [epel-6]
bugzilla·2013-08-07·CVSS 2.1
CVE-2013-4183 [LOW] CVE-2013-4183 openstack-cinder: OpenStack: Cinder LVM volume driver does not support secure deletion [epel-6]
CVE-2013-4183 openstack-cinder: OpenStack: Cinder LVM volume driver does not support secure deletion [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when av
Bugzilla
CVE-2013-4183 OpenStack: Cinder LVM volume driver does not support secure deletion
bugzilla·2013-08-07·CVSS 2.1
CVE-2013-4183 [LOW] CVE-2013-4183 OpenStack: Cinder LVM volume driver does not support secure deletion
CVE-2013-4183 OpenStack: Cinder LVM volume driver does not support secure deletion
Jeremy Stanley reports:
Title: Cinder LVM volume driver does not support secure deletion
Reporter: Rongze Zhu (UnitedStack)
Products: Cinder
Affects: 2013.1 (Grizzly) and later
Description:
Rongze Zhu from UnitedStack reported a vulnerability in the Cinder
LVM volume driver. The contents of LVM snapshots may not be cleared
upon deletion even when secure deletes are configured, resulting in
potential exposure of latent data to subsequent servers for other
tenants. Only setups using LVMVolumeDriver are affected.
Havana (development branch) fix:
https://review.openstack.org/36506
Grizzly fix:
https://review.openstack.org/39565
Notes:
This fix is included in the havana-2 development milestone and will
appe
Bugzilla
CVE-2013-4183 openstack-cinder: OpenStack: Cinder LVM volume driver does not support secure deletion [openstack-rdo]
bugzilla·2013-08-07·CVSS 2.1
CVE-2013-4183 [LOW] CVE-2013-4183 openstack-cinder: OpenStack: Cinder LVM volume driver does not support secure deletion [openstack-rdo]
CVE-2013-4183 openstack-cinder: OpenStack: Cinder LVM volume driver does not support secure deletion [openstack-rdo]
openstack-rdo tracking bug for openstack-cinder: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the blocked bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Fixed in:
openstack-cinder-2013.1.3-1 [el6-grizzly]
openstack-cinder-2013.2-0.8.b3 [el6-havana]
Bugzilla
CVE-2013-4183 openstack-cinder: OpenStack: Cinder LVM volume driver does not support secure deletion [fedora-all]
bugzilla·2013-08-07·CVSS 2.1
CVE-2013-4183 [LOW] CVE-2013-4183 openstack-cinder: OpenStack: Cinder LVM volume driver does not support secure deletion [fedora-all]
CVE-2013-4183 openstack-cinder: OpenStack: Cinder LVM volume driver does not support secure deletion [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when ava
2013-09-16
Published