CVE 2013-4183
The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors.
Related bugs and status
CVE-2013-4183 (Candidate) is related to these bugs:
Bug #1198185: [OSSA 2013-021] Cinder LVM volume driver does not support secure deletion (CVE-2013-4183)
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1198185 | [OSSA 2013-021] Cinder LVM volume driver does not support secure deletion (CVE-2013-4183) | Cinder | High | Fix Released | ||
1198185 | [OSSA 2013-021] Cinder LVM volume driver does not support secure deletion (CVE-2013-4183) | OpenStack Security Advisory | Medium | Fix Released | ||
1198185 | [OSSA 2013-021] Cinder LVM volume driver does not support secure deletion (CVE-2013-4183) | Cinder grizzly | High | Fix Released |
Bug #1210447: Meta bug for tracking Openstack 2013.1.3 Stable Update
See the
CVE page on Mitre.org
for more details.