CVE-2013-4183: Infoleak
Published Sep 16, 2013
·Updated
The clearvolume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors.
Affected Software
3 affected componentsFixes available
pip/cinder<7.0.0a0
7.0.0a0
Openstack Cinder=2013.1.1
Openstack Cinder=2013.1.2
Remediation
Patch Available
Event History
Sep 16, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·04:58 AM
Frequently Asked Questions
1
What is the severity of CVE-2013-4183?
CVE-2013-4183 is classified as a medium severity vulnerability.
2
How do I fix CVE-2013-4183?
To fix CVE-2013-4183, upgrade OpenStack Cinder to version 7.0.0a0 or later.
3
What impact does CVE-2013-4183 have on my system?
CVE-2013-4183 allows local users to potentially access sensitive data from deleted snapshots.
4
Which versions of OpenStack Cinder are affected by CVE-2013-4183?
CVE-2013-4183 affects OpenStack Cinder versions 2013.1.1 and 2013.1.2.
5
Who is potentially affected by CVE-2013-4183?
Local users of systems running the affected versions of OpenStack Cinder may be at risk due to CVE-2013-4183.