python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
2018-05-08T17:29:00.560
2024-11-21T03:23:47.420
Modified
CVSSv3.0: 5.9 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openstack | oslo.middleware | ≤ 3.8.0 | Yes |
Application | openstack | oslo.middleware | ≤ 3.19.0 | Yes |
Application | openstack | oslo.middleware | ≤ 3.23.0 | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |