QID 980794
QID 980794: Python (pip) Security Update for oslo.middleware (GHSA-xcp8-hh74-f6mc)
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-xcp8-hh74-f6mc for updates pertaining to this vulnerability.
Vendor References
- GHSA-xcp8-hh74-f6mc -
github.com/advisories/GHSA-xcp8-hh74-f6mc
CVEs related to QID 980794
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xcp8-hh74-f6mc | oslo.middleware |
|