Executive brief
Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.
Affected products
- PyPI apache-libcloud
Junglewise Threat Intelligence
CVE-2013-6480 · Severity: info · Published 2014-01-07
Technologies: apache-libcloud (PyPI). Vendors: PyPI.
Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.