python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
References
Configurations
History
No history.
Information
Published : 2018-05-08 17:29
Updated : 2024-11-21 03:23
NVD link : CVE-2017-2592
Mitre link : CVE-2017-2592
CVE.ORG link : CVE-2017-2592
JSON object : View
Products Affected
canonical
- ubuntu_linux
openstack
- oslo.middleware
CWE
CWE-532
Insertion of Sensitive Information into Log File