5.9
CVE-2017-2592
- EPSS 0.1%
- Published 08.05.2018 17:29:00
- Last modified 21.11.2024 03:23:47
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
Data is provided by the National Vulnerability Database (NVD)
Openstack ≫ Oslo.Middleware Version <= 3.8.0
Openstack ≫ Oslo.Middleware Version >= 3.9.0 <= 3.19.0
Openstack ≫ Oslo.Middleware Version >= 3.20.0 <= 3.23.0
Canonical ≫ Ubuntu Linux Version16.04 SwEditionlts
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.1% | 0.241 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
secalert@redhat.com | 5.9 | 1.5 | 4 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.