Vulnerability Description
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openstack | Oslo.Middleware | <= 3.8.0 |
| Canonical | Ubuntu Linux | 16.04 |
Related Weaknesses (CWE)
References
- http://lists.openstack.org/pipermail/openstack-announce/2017-January/002002.htmlPatchVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0300.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0435.htmlThird Party Advisory
- http://www.securityfocus.com/bid/95827Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:0300Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:0435Third Party Advisory
- https://bugs.launchpad.net/keystonemiddleware/+bug/1628031Issue TrackingPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2592Issue TrackingPatchThird Party Advisory
- https://review.openstack.org/#/c/425730/Issue TrackingPatchVendor Advisory
- https://review.openstack.org/#/c/425732/Issue TrackingPatchVendor Advisory
- https://review.openstack.org/#/c/425734/Issue TrackingPatchVendor Advisory
- https://usn.ubuntu.com/3666-1/Third Party Advisory
- http://lists.openstack.org/pipermail/openstack-announce/2017-January/002002.htmlPatchVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0300.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0435.htmlThird Party Advisory
FAQ
What is CVE-2017-2592?
CVE-2017-2592 is a vulnerability with a CVSS score of 5.9 (MEDIUM). python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error messa...
How severe is CVE-2017-2592?
CVE-2017-2592 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-2592?
Check the references section above for vendor advisories and patch information. Affected products include: Openstack Oslo.Middleware, Canonical Ubuntu Linux.