Описание
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
An information-disclosure flaw was found in oslo.middleware. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse) | python-oslo-middleware | Not affected | ||
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | python-oslo-middleware | Not affected | ||
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | python-oslo-middleware | Not affected | ||
| Red Hat Gluster Storage 3.1 | python-oslo-middleware | Not affected | ||
| Red Hat OpenStack Platform 11 (Ocata) | python-oslo-middleware | Not affected | ||
| Red Hat OpenStack Platform 8 (Liberty) | python-oslo-middleware | Not affected | ||
| Red Hat OpenStack Platform 10.0 (Newton) | python-oslo-middleware | Fixed | RHSA-2017:0300 | 22.02.2017 |
| Red Hat OpenStack Platform 9.0 (Mitaka) | python-oslo-middleware | Fixed | RHSA-2017:0435 | 02.03.2017 |
Показывать по
Дополнительная информация
Статус:
5.9 Medium
CVSS3
Связанные уязвимости
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulner ...
oslo.middleware Information Disclosure vulnerability
5.9 Medium
CVSS3