CVE-2013-6480

EPSS 0.56%

Libcloud does not properly scrub data when destroying a DigitalOcean node

Published: 5/14/2022Modified: 12/8/2024

Description

Libcloud 0.12.3 through 0.13.2 does not set the `scrub_data parameter` for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.

Affected packages (2)

References (15)