CVE-2013-6480
published 2014-01-07CVE-2013-6480: Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information…
PriorityP415low2.1CVSS 2.0
AVLACLAuNCPINAN
EXPLOIT
EPSS
2.06%
79.2th percentile
Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | libcloud | — | — |
| apache | libcloud | — | — |
| apache | libcloud | — | — |
| apache | libcloud | — | — |
| apache | libcloud | — | — |
| debian | libcloud | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_debian2.1LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Libcloud does not properly scrub data when destroying a DigitalOcean node
ghsa·2022-05-14
CVE-2013-6480 [LOW] CWE-200 Libcloud does not properly scrub data when destroying a DigitalOcean node
Libcloud does not properly scrub data when destroying a DigitalOcean node
Libcloud 0.12.3 through 0.13.2 does not set the `scrub_data parameter` for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.
OSV
Libcloud does not properly scrub data when destroying a DigitalOcean node
osv·2022-05-14
CVE-2013-6480 [LOW] Libcloud does not properly scrub data when destroying a DigitalOcean node
Libcloud does not properly scrub data when destroying a DigitalOcean node
Libcloud 0.12.3 through 0.13.2 does not set the `scrub_data parameter` for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.
OSV
CVE-2013-6480: Libcloud 0
osv·2014-01-07
CVE-2013-6480 CVE-2013-6480: Libcloud 0
Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.
Debian
CVE-2013-6480: libcloud - Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the des...
vendor_debian·2013·CVSS 2.1
CVE-2013-6480 [LOW] CVE-2013-6480: libcloud - Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the des...
Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
Bugzilla
CVE-2013-6480 python-libcloud: doesn't send scrub_data query parameter when destroying a DigitalOcean node [fedora-all]
bugzilla·2014-01-02·CVSS 2.1
CVE-2013-6480 [LOW] CVE-2013-6480 python-libcloud: doesn't send scrub_data query parameter when destroying a DigitalOcean node [fedora-all]
CVE-2013-6480 python-libcloud: doesn't send scrub_data query parameter when destroying a DigitalOcean node [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field wh
Bugzilla
CVE-2013-6480 python-libcloud: doesn't send scrub_data query parameter when destroying a DigitalOcean node
bugzilla·2014-01-02·CVSS 2.1
CVE-2013-6480 [LOW] CVE-2013-6480 python-libcloud: doesn't send scrub_data query parameter when destroying a DigitalOcean node
CVE-2013-6480 python-libcloud: doesn't send scrub_data query parameter when destroying a DigitalOcean node
DigitalOcean recently changed the default API behavior from scrub to non-scrub when destroying a VM.
Libcloud doesn't explicitly send "scrub_data" query parameter when destroying a node. This means nodes which are destroyed using Libcloud are vulnerable to later customers stealing data contained on them. Only users who are using DigitalOcean driver are known to be affected by this issue.
The issue is said to be fixed in the version 0.13.3.
References:
http://seclists.org/fulldisclosure/2014/Jan/11
http://libcloud.apache.org/security.html
https://digitalocean.com/blog_posts/transparency-regarding-data-security
https://github.com/fog/fog/issues/2525
Commit:
https://github.com/apach
http://libcloud.apache.org/security.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00015.htmlhttp://www.securityfocus.com/archive/1/530624/100/0/threadedhttp://www.securityfocus.com/bid/64617https://digitalocean.com/blog_posts/transparency-regarding-data-securityhttps://github.com/fog/fog/issues/2525http://libcloud.apache.org/security.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00015.htmlhttp://www.securityfocus.com/archive/1/530624/100/0/threadedhttp://www.securityfocus.com/bid/64617https://digitalocean.com/blog_posts/transparency-regarding-data-securityhttps://github.com/fog/fog/issues/2525
2014-01-07
Published