Lucene search

K
cve[email protected]CVE-2013-6480
HistoryJan 07, 2014 - 6:55 p.m.

CVE-2013-6480

2014-01-0718:55:07
CWE-200
web.nvd.nist.gov
28
libcloud
digitalocean
api
security
vulnerability
nvd

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.5 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

18.2%

Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.

Affected configurations

NVD
Node
apachelibcloudMatch0.12.3
OR
apachelibcloudMatch0.12.4
OR
apachelibcloudMatch0.13.0
OR
apachelibcloudMatch0.13.1
OR
apachelibcloudMatch0.13.2

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.5 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

18.2%