ISOMAN

CVE

CVE-2017-2592

python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).

Severity
MEDIUM
CVSS
5.9
Published
Modified

Linked Releases

References

  1. http://lists.openstack.org/pipermail/openstack-announce/2017-January/002002.html
  2. http://rhn.redhat.com/errata/RHSA-2017-0300.html
  3. http://rhn.redhat.com/errata/RHSA-2017-0435.html
  4. http://www.securityfocus.com/bid/95827
  5. https://access.redhat.com/errata/RHSA-2017:0300
  6. https://access.redhat.com/errata/RHSA-2017:0435
  7. https://bugs.launchpad.net/keystonemiddleware/+bug/1628031
  8. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2592
  9. https://review.openstack.org/#/c/425730/
  10. https://review.openstack.org/#/c/425732/
  11. https://review.openstack.org/#/c/425734/
  12. https://usn.ubuntu.com/3666-1/
  13. http://lists.openstack.org/pipermail/openstack-announce/2017-January/002002.html
  14. http://rhn.redhat.com/errata/RHSA-2017-0300.html
  15. http://rhn.redhat.com/errata/RHSA-2017-0435.html
  16. http://www.securityfocus.com/bid/95827
  17. https://access.redhat.com/errata/RHSA-2017:0300
  18. https://access.redhat.com/errata/RHSA-2017:0435
  19. https://bugs.launchpad.net/keystonemiddleware/+bug/1628031
  20. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2592