CVE-2017-2592 python-oslo-middleware: CatchErrors leaks sensitive values into error logs
Issue
- CVE-2017-2592 python-oslo-middleware: CatchErrors leaks sensitive values into error logs
An information disclosure vulnerability in oslo.middleware was found. Software using the CatchError class may include sensitive values in the error message accompanying a Traceback, resulting in their disclosure. For example, complete API requests (including keystone tokens in their headers) may leak into neutron error logs.
Affected versions: <=3.8.0, >=3.9.0 <=3.19.0, >=3.20.0 <=3.22.0
Environment
- Red Hat OpenStack Platform
- python-oslo-middleware
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.