← Vulnerability feed

Vulnerability record · CVE-2013-4183 · published 16 September 2013

CVE-2013-4183: Openstack cinder information exposure vulnerability

Openstack · Cinder

The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors.

2.1 CVSS 2.0 Low EPSS 0.41% · top 67.7% CWE-200 · Information exposure
2.1CVSS 2.0 base score
0.41%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors.

AV:L/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-4183 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2017-15139Openstack cinder information exposure vulnerabilityA vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configura…EPSS 1.2%7.5CVE-2015-5162Openstack cinder vulnerabilityThe image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not prope…EPSS 3.1%6.5CVE-2024-32498Openstack cinder vulnerabilityAn issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom …EPSS 0.84%5.7CVE-2022-47951Openstack cinder path traversal vulnerabilityAn issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and …EPSS 1.0%4.3CVE-2013-4202Openstack cinder vulnerabilityThe (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier al…EPSS 2.6%4.0CVE-2014-3641Openstack cinder information exposure vulnerabilityThe (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cind…EPSS 1.9%2.1CVE-2014-7230Openstack cinder information exposure vulnerabilityThe processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users …EPSS 0.49%2.1CVE-2014-7231Openstack cinder information exposure vulnerabilityThe strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does no…EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2013-4183), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.