cbcvebase.
CVE-2017-2592
published 2018-05-08

CVE-2017-2592: python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include…

PriorityP421medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.47%
38.0th percentile
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).

Affected

8 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debianpython-oslo.middleware< python-oslo.middleware 3.19.0-3 (bookworm)python-oslo.middleware 3.19.0-3 (bookworm)
openstackoslo.middleware<= 3.8.0
openstackoslo.middleware>= 0 < 3.8.13.8.1
openstackoslo.middleware>= 3.20.0 < 3.23.13.23.1
openstackoslo.middleware3.20.0 – 3.23.0
openstackoslo.middleware>= 3.9.0 < 3.19.13.19.1
openstackoslo.middleware3.9.0 – 3.19.0

CVSS provenance

nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.