Libcloud doesn't send scrub_data query parameter

2014.01.02
Credit: Tomaz Muraus
Risk: Low
Local: No
Remote: Yes
CWE: CWE-200


CVSS Base Score: 2.1/10
Impact Subscore: 2.9/10
Exploitability Subscore: 3.9/10
Exploit range: Local
Attack complexity: Low
Authentication: No required
Confidentiality impact: Partial
Integrity impact: None
Availability impact: None

[CVE-2013-6480] Libcloud doesn't send scrub_data query parameter when destroying a DigitalOcean node Severity: Low Vendor: Apache Software Foundation Project: Apache Libcloud (http://libcloud.apache.org/) Affected Versions: Apache Libcloud 0.12.3 to 0.13.3 (version prior to 0.12.3 don't include a DigitalOcean driver) Description: DigitalOcean recently changed the default API behavior from scrub to non-scrub when destroying a VM. Libcloud doesn't explicitly send "scrub_data" query parameter when destroying a node. This means nodes which are destroyed using Libcloud are vulnerable to later customers stealing data contained on them. Note: Only users who are using DigitalOcean driver are affected by this issue. References: - - http://libcloud.apache.org/security.html - - https://digitalocean.com/blog_posts/transparency-regarding-data-security - - https://github.com/fog/fog/issues/2525 Mitigation: This vulnerability has been fixed in version 0.13.3. Users who use DigitalOcean driver are strongly encouraged to upgrade to this release.

References:

http://libcloud.apache.org/security.html
https://digitalocean.com/blog_posts/transparency-regarding-data-security
https://github.com/fog/fog/issues/2525
http://seclists.org/fulldisclosure/2014/Jan/11


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2021, cxsecurity.com

 

Back to Top