CVE-2017-2592
Summary
| CVE | CVE-2017-2592 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-08 17:29:00 UTC |
| Updated | 2019-10-09 23:26:00 UTC |
| Description | python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Gerrit Code Review |
MISC |
review.openstack.org |
Issue Tracking, Patch, Vendor Advisory |
| 1414698 – (CVE-2017-2592) CVE-2017-2592 python-oslo-middleware: CatchErrors leaks sensitive values into error logs |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| OpenStack oslo.middleware CVE-2017-2592 Information Disclosure Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Gerrit Code Review |
MISC |
review.openstack.org |
Issue Tracking, Patch, Vendor Advisory |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Third Party Advisory |
| USN-3666-1: Oslo middleware vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Red Hat Customer Portal |
CONFIRM |
access.redhat.com |
Third Party Advisory |
| OpenStack Open Source Cloud Computing Software » Message: [openstack-announce] [OSSA-2017-001] CatchErrors leaks sensitive values in oslo.middleware (CVE-2017-2592) |
CONFIRM |
lists.openstack.org |
Patch, Vendor Advisory |
| Red Hat Customer Portal |
CONFIRM |
access.redhat.com |
Third Party Advisory |
| Bug #1628031 “[OSSA-2017-001] CatchErrors leaks sensitive values...” : Bugs : keystonemiddleware |
MISC |
bugs.launchpad.net |
Issue Tracking, Patch, Third Party Advisory |
| Gerrit Code Review |
MISC |
review.openstack.org |
Issue Tracking, Patch, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980794 Python (pip) Security Update for oslo.middleware (GHSA-xcp8-hh74-f6mc)