—
PYSEC-2018-104
Quick fix
PYSEC-2018-104 — oslo-middleware: upgrade to the fixed version with the command below.
pip install --upgrade 'oslo-middleware>=3.8.1'Details
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/oslo-middleware
Introduced in:
3.9.0Fixed in: 3.19.1Fix
pip install --upgrade 'oslo-middleware>=3.8.1'References
- https://review.openstack.org/#/c/425734/[WEB]
- https://review.openstack.org/#/c/425732/[WEB]
- https://review.openstack.org/#/c/425730/[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2592[REPORT]
- https://bugs.launchpad.net/keystonemiddleware/+bug/1628031[WEB]
- https://access.redhat.com/errata/RHSA-2017:0435[ADVISORY]
- https://access.redhat.com/errata/RHSA-2017:0300[ADVISORY]
- http://lists.openstack.org/pipermail/openstack-announce/2017-January/002002.html[WEB]
- http://www.securityfocus.com/bid/95827[WEB]
- http://rhn.redhat.com/errata/RHSA-2017-0435.html[ADVISORY]
- http://rhn.redhat.com/errata/RHSA-2017-0300.html[ADVISORY]
- https://usn.ubuntu.com/3666-1/[WEB]
- https://github.com/advisories/GHSA-xcp8-hh74-f6mc[ADVISORY]