CVE-2017-2592
published 2018-05-08CVE-2017-2592: python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include…
PriorityP421medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.47%
38.0th percentile
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | python-oslo.middleware | < python-oslo.middleware 3.19.0-3 (bookworm) | python-oslo.middleware 3.19.0-3 (bookworm) |
| openstack | oslo.middleware | <= 3.8.0 | — |
| openstack | oslo.middleware | >= 0 < 3.8.1 | 3.8.1 |
| openstack | oslo.middleware | >= 3.20.0 < 3.23.1 | 3.23.1 |
| openstack | oslo.middleware | 3.20.0 – 3.23.0 | — |
| openstack | oslo.middleware | >= 3.9.0 < 3.19.1 | 3.19.1 |
| openstack | oslo.middleware | 3.9.0 – 3.19.0 | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
oslo.middleware Information Disclosure vulnerability
ghsa·2018-07-13
CVE-2017-2592 [HIGH] CWE-532 oslo.middleware Information Disclosure vulnerability
oslo.middleware Information Disclosure vulnerability
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
OSV
oslo.middleware Information Disclosure vulnerability
osv·2018-07-13
CVE-2017-2592 [HIGH] oslo.middleware Information Disclosure vulnerability
oslo.middleware Information Disclosure vulnerability
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
OSV
CVE-2017-2592: python-oslo-middleware before versions 3
osv·2018-05-08·CVSS 5.5
CVE-2017-2592 [MEDIUM] CVE-2017-2592: python-oslo-middleware before versions 3
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
Ubuntu
Oslo middleware vulnerability
vendor_ubuntu·2018-05-31
CVE-2017-2592 Oslo middleware vulnerability
Title: Oslo middleware vulnerability
Summary: Applications using Oslo middleware could be made to expose sensitive
information.
Divya K Konoor discovered Oslo middleware was vulnerable to an information
disclosure. A local attacker could exploit this flaw to obtain sensitive
information from OpenStack component error logs.
Instructions: After a standard system update you need to restart OpenStack services to
make all the necessary changes.
Red Hat
python-oslo-middleware: CatchErrors leaks sensitive values into error logs
vendor_redhat·2017-01-26·CVSS 5.9
CVE-2017-2592 [MEDIUM] CWE-532 python-oslo-middleware: CatchErrors leaks sensitive values into error logs
python-oslo-middleware: CatchErrors leaks sensitive values into error logs
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
An information-disclosure flaw was found in oslo.middleware. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
Package: python-oslo-middleware (Red Hat Enterprise Linux OpenStack Platform 5 (Iceh
Debian
CVE-2017-2592: python-oslo.middleware - python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an...
vendor_debian·2017·CVSS 5.9
CVE-2017-2592 [MEDIUM] CVE-2017-2592: python-oslo.middleware - python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an...
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
Scope: local
bookworm: resolved (fixed in 3.19.0-3)
bullseye: resolved (fixed in 3.19.0-3)
forky: resolved (fixed in 3.19.0-3)
sid: resolved (fixed in 3.19.0-3)
trixie: resolved (fixed in 3.19.0-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-2592 python-oslo-middleware: CatchErrors leaks sensitive values into error logs [fedora-all]
bugzilla·2017-01-30·CVSS 5.9
CVE-2017-2592 [MEDIUM] CVE-2017-2592 python-oslo-middleware: CatchErrors leaks sensitive values into error logs [fedora-all]
CVE-2017-2592 python-oslo-middleware: CatchErrors leaks sensitive values into error logs [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CatchErrors leaks sensitive values in oslo.middleware (CVE-2017-2592)
bugzilla·2017-01-30·CVSS 5.9
CVE-2017-2592 [MEDIUM] CatchErrors leaks sensitive values in oslo.middleware (CVE-2017-2592)
CatchErrors leaks sensitive values in oslo.middleware (CVE-2017-2592)
Description of problem:
If an exception is caught by the catch_errors middleware the entire
request is dumped into the log including sensitive information like
tokens. Filter that information before outputting the failed request.
Version-Release number of selected component (if applicable):
# rpm -qf /usr/lib/python2.7/site-packages/neutron/openstack/common/middleware/catch_errors.py
python-neutron-2014.1.5-15.el7ost.noarch
https://bugs.launchpad.net/keystonemiddleware/+bug/1628031
Discussion:
Hello Martin, this issue is being analysed in the #1414698, I have unembargoed it now. Please attach the customer case there and let us know at [email protected] if there is anything missing.
Thanks!
*** This bug has been
Bugzilla
CVE-2017-2592 python-oslo-middleware: CatchErrors leaks sensitive values into error logs [openstack-rdo]
bugzilla·2017-01-30·CVSS 5.9
CVE-2017-2592 [MEDIUM] CVE-2017-2592 python-oslo-middleware: CatchErrors leaks sensitive values into error logs [openstack-rdo]
CVE-2017-2592 python-oslo-middleware: CatchErrors leaks sensitive values into error logs [openstack-rdo]
This as an RDO Project security tracking bug against python-oslo-middleware. It was created
to ensure that one or more security vulnerabilities are fixed.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
[bug automatically created by: add-tracking-bugs]
Discussion:
Tracking bug closed so closing this one.
Bugzilla
CVE-2017-2592 python-oslo-middleware: CatchErrors leaks sensitive values into error logs
bugzilla·2017-01-19·CVSS 5.9
CVE-2017-2592 [MEDIUM] CVE-2017-2592 python-oslo-middleware: CatchErrors leaks sensitive values into error logs
CVE-2017-2592 python-oslo-middleware: CatchErrors leaks sensitive values into error logs
An information disclosure vulnerability in oslo.middleware was found. Software using the CatchError class may include sensitive values in the error message accompanying a Traceback, resulting in their disclosure. For example, complete API requests (including keystone tokens in their headers) may leak into neutron error logs.
Affected versions: =3.9.0 =3.20.0 <=3.22.0
Discussion:
Acknowledgments:
Name: the OpenStack project
Upstream: Divya K Konoor (IBM)
---
Created attachment 1243810
Ocata patch
---
Created attachment 1243811
Newton patch
---
Created attachment 1243812
Mitaka patch
---
Created python-oslo-middleware tracking bugs for this issue:
Affects: openstack-rdo [bug 1417592]
Affect
http://lists.openstack.org/pipermail/openstack-announce/2017-January/002002.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0300.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0435.htmlhttp://www.securityfocus.com/bid/95827https://access.redhat.com/errata/RHSA-2017:0300https://access.redhat.com/errata/RHSA-2017:0435https://bugs.launchpad.net/keystonemiddleware/+bug/1628031https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2592https://review.openstack.org/#/c/425730/https://review.openstack.org/#/c/425732/https://review.openstack.org/#/c/425734/https://usn.ubuntu.com/3666-1/http://lists.openstack.org/pipermail/openstack-announce/2017-January/002002.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0300.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0435.htmlhttp://www.securityfocus.com/bid/95827https://access.redhat.com/errata/RHSA-2017:0300https://access.redhat.com/errata/RHSA-2017:0435https://bugs.launchpad.net/keystonemiddleware/+bug/1628031https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2592https://review.openstack.org/#/c/425730/https://review.openstack.org/#/c/425732/https://review.openstack.org/#/c/425734/https://usn.ubuntu.com/3666-1/
2018-05-08
Published