CVE-2013-6480: Apache Libcloud
Low severity, CVSS 2.1. EPSS: 2.1% chance of exploitation in the next 30 days.
Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.
Affected products
- Apache Libcloud: version 0.12.3 only; version 0.12.4 only; version 0.13.0 only; version 0.13.1 only; version 0.13.2 only
Published 2014-01-07. Last modified 2026-06-17.