Описание
oslo.middleware Information Disclosure vulnerability
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2017-2592
- https://access.redhat.com/errata/RHSA-2017:0300
- https://access.redhat.com/errata/RHSA-2017:0435
- https://bugs.launchpad.net/keystonemiddleware/+bug/1628031
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2592
- https://github.com/advisories/GHSA-xcp8-hh74-f6mc
- https://github.com/pypa/advisory-database/tree/main/vulns/oslo-middleware/PYSEC-2018-104.yaml
- https://review.openstack.org/#/c/425730
- https://review.openstack.org/#/c/425732
- https://review.openstack.org/#/c/425734
- https://usn.ubuntu.com/3666-1
- http://lists.openstack.org/pipermail/openstack-announce/2017-January/002002.html
- http://rhn.redhat.com/errata/RHSA-2017-0300.html
- http://rhn.redhat.com/errata/RHSA-2017-0435.html
Пакеты
oslo.middleware
>= 3.9.0, < 3.19.1
3.19.1
oslo.middleware
< 3.8.1
3.8.1
oslo.middleware
>= 3.20.0, < 3.23.1
3.23.1
oslo-middleware
>= 3.9.0, < 3.19.1
3.19.1
oslo-middleware
< 3.8.1
3.8.1
oslo-middleware
>= 3.20.0, < 3.23.1
3.23.1
Связанные уязвимости
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulner ...