2.1
CVSSv2

CVE-2013-4183

Published: 16/09/2013 Updated: 31/10/2013
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 up to and including 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

openstack cinder 2013.1.1

openstack cinder 2013.1.2

Vendor Advisories

Synopsis Moderate: openstack-cinder security update Type/Severity Security Advisory: Moderate Topic Updated openstack-cinder packages that fix two security issues are nowavailable for Red Hat OpenStack 30The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vul ...
Cinder could be made to crash or expose sensitive information ...
Debian Bug report logs - #719010 cinder: CVE-2013-4183: Cinder LVM volume driver does not support secure deletion Package: cinder; Maintainer for cinder is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 7 Aug 2013 18:12:02 UTC Severity: importan ...
Debian Bug report logs - #719118 CVE-2013-4202: DoS using XML entities in extensions Package: cinder; Maintainer for cinder is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Thomas Goirand <zigo@debianorg> Date: Thu, 8 Aug 2013 14:15:01 UTC Severity: important Tags: patch, security Found in ver ...
The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 201311 through 201312 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors ...