CVE-2013-6480
Libcloud does not properly scrub data when destroying a DigitalOcean node
EPSS 2.1%
描述
Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.
如何修補 CVE-2013-6480
要修補 CVE-2013-6480,請將受影響套件升級到下列已修補版本。
- PyPI/apache-libcloud—升級至 0.13.3 或更新版本
- PyPI/apache-libcloud—升級至 0.13.3 或更新版本
CVE-2013-6480 正在被利用嗎?
低 — EPSS 為 2.1%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- >= 0.12.3, < 0.13.3
- >= 0.12.3, < 0.13.3