5.5

CVE-2017-2592

python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openstack ≫ Oslo.Middleware Version <= 3.8.0
Openstack ≫ Oslo.Middleware Version >= 3.9.0 <= 3.19.0
Openstack ≫ Oslo.Middleware Version >= 3.20.0 <= 3.23.0
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.367
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat 5.9 1.5 4
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

http://lists.openstack.org/pipermail/openstack-announce/2017-January/002002.html
Patch
Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2017-0300.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0435.html
Third Party Advisory
http://www.securityfocus.com/bid/95827
Third Party Advisory
VDB Entry
https://access.redhat.com/errata/RHSA-2017:0300
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:0435
Third Party Advisory
https://bugs.launchpad.net/keystonemiddleware/+bug/1628031
Patch
Third Party Advisory
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2592
Patch
Third Party Advisory
Issue Tracking
https://review.openstack.org/#/c/425730/
Patch
Vendor Advisory
Issue Tracking
https://review.openstack.org/#/c/425732/
Patch
Vendor Advisory
Issue Tracking
https://review.openstack.org/#/c/425734/
Patch
Vendor Advisory
Issue Tracking
https://usn.ubuntu.com/3666-1/
Third Party Advisory