Description
The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-0003 | The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors. |
Github GHSA |
GHSA-q3rw-wcj6-8cjf | OpenStack Cinder LVMVolumeDriver does not zero deleted snapshots |
Ubuntu USN |
USN-2005-1 | Cinder vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T16:38:01.539Z
Reserved: 2013-06-12T00:00:00.000Z
Link: CVE-2013-4183
No data.
Status : Modified
Published: 2013-09-16T19:14:38.833
Modified: 2026-04-29T01:13:23.040
Link: CVE-2013-4183
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA
Ubuntu USN