python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an...
Vulnerability Description
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-2592
Credits & Attribution
No credits recorded in the NVD database.
References
- https://review.openstack.org/#/c/425732/
- http://lists.openstack.org/pipermail/openstack-announce/2017-January/002002.html
- http://rhn.redhat.com/errata/RHSA-2017-0300.html
- https://access.redhat.com/errata/RHSA-2017:0300
- http://rhn.redhat.com/errata/RHSA-2017-0435.html
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2592
- http://www.securityfocus.com/bid/95827
- https://review.openstack.org/#/c/425730/
- https://review.openstack.org/#/c/425734/
- https://bugs.launchpad.net/keystonemiddleware/+bug/1628031
- https://access.redhat.com/errata/RHSA-2017:0435
- https://usn.ubuntu.com/3666-1/
More from unspecified
View All →Affected Vendor
unspecified
View all reports →