CVE-2017-2592
MEDIUMOpenstack Oslo.middleware < 3.8.0 - Log Information Exposure
Title source: ruleDescription
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
References (12)
Scores
CVSS v3
5.9
EPSS
0.0009
EPSS Percentile
26.0%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Classification
CWE
CWE-532
Status
published
Affected Products (4)
openstack/oslo.middleware
< 3.8.0
canonical/ubuntu_linux
pypi/oslo.middleware
< 3.19.1PyPI
pypi/oslo-middleware
< 3.19.1PyPI
Timeline
Published
May 08, 2018
Tracked Since
Feb 18, 2026