CVE-2013-6480

Apache Libcloud 0.12.3-0.13.2 - Exposure of Sensitive Information via DigitalOcean Destroy API

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-6480. PoCs published by anonymous.

AI-analyzed exploit summary The provided text describes a local information-disclosure vulnerability in Apache Libcloud versions 0.12.3 through 0.13.2. The included command is a generic Linux command to dump and extract strings from a disk, which is unrelated to the vulnerability itself.

Description

Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.

Exploits (1)

exploitdb WRITEUP VERIFIED
by anonymous · textlocallinux
https://www.exploit-db.com/exploits/38937

The provided text describes a local information-disclosure vulnerability in Apache Libcloud versions 0.12.3 through 0.13.2. The included command is a generic Linux command to dump and extract strings from a disk, which is unrelated to the vulnerability itself.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: Apache Libcloud 0.12.3 through 0.13.2
No auth needed
Prerequisites: Local access to the system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/64617
Vendor Advisory x_refsource_confirm
http://libcloud.apache.org/security.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/530624/100/0/threaded
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2014-02/msg00015.html
Issue Tracking x_refsource_misc
https://github.com/fog/fog/issues/2525

Scores

EPSS 0.0056
EPSS Percentile 69.0%

Details

CWE
CWE-200
Status published
Products (6)
apache/libcloud 0.12.3
apache/libcloud 0.12.4
apache/libcloud 0.13.0
apache/libcloud 0.13.1
apache/libcloud 0.13.2
pypi/apache-libcloud 0.12.3 - 0.13.3PyPI
Published Jan 07, 2014
Tracked Since Feb 18, 2026