2.1

CVE-2013-6480

Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Libcloud Version 0.12.3
Apache ≫ Libcloud Version 0.12.4
Apache ≫ Libcloud Version 0.13.0
Apache ≫ Libcloud Version 0.13.1
Apache ≫ Libcloud Version 0.13.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.08% 0.796
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://libcloud.apache.org/security.html
Vendor Advisory
http://lists.opensuse.org/opensuse-updates/2014-02/msg00015.html
http://www.securityfocus.com/archive/1/530624/100/0/threaded
http://www.securityfocus.com/bid/64617
https://digitalocean.com/blog_posts/transparency-regarding-data-security
https://github.com/fog/fog/issues/2525