CVE-2017-2592: Medium severity openstack keystonemiddleware vulnerability
An information disclosure vulnerability in oslo.middleware was found. Software using the CatchError class may include sensitive values in the error message accompanying a Traceback, resulting in their disclosure. For example, complete API requests (including keystone tokens in their headers) may leak into neutron error logs.
Affected versions: <=3.8.0, >=3.9.0 <=3.19.0, >=3.20.0 <=3.22.0
Other sources
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2592?
CVE-2017-2592 is classified as an information disclosure vulnerability, which can expose sensitive data.
How do I fix CVE-2017-2592?
To resolve CVE-2017-2592, update to a version of oslo.middleware that is 3.8.1 or later, or 3.19.1 or later, or 3.23.1 or later depending on your package manager.
What could be potentially exposed due to CVE-2017-2592?
CVE-2017-2592 could expose sensitive values such as keystone tokens included in error messages.
Which versions of oslo.middleware are affected by CVE-2017-2592?
Versions of oslo.middleware prior to 3.8.1, between 3.9.0 and 3.19.0, and between 3.20.0 and 3.23.0 are affected by CVE-2017-2592.
Is CVE-2017-2592 specific to a particular operating system?
CVE-2017-2592 is not limited to a specific operating system, but it has been noted in software distributions like Red Hat and Debian.