VDB
Sign up
—

PYSEC-2018-104

Quick fix

PYSEC-2018-104 — oslo-middleware: upgrade to the fixed version with the command below.

pip install --upgrade 'oslo-middleware>=3.8.1'

Details

python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/oslo-middleware
Introduced in: 3.9.0Fixed in: 3.19.1
Fixpip install --upgrade 'oslo-middleware>=3.8.1'

References