python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
| Software | From | Fixed in |
|---|---|---|
| openstack / oslo.middleware | - | 3.8.0.x |
| openstack / oslo.middleware | 3.9.0 | 3.19.0.x |
| openstack / oslo.middleware | 3.20.0 | 3.23.0.x |
| canonical / ubuntu_linux | 16.04 | 16.04.x |
oslo.middleware
|
3.9.0 | 3.19.1 |
oslo.middleware
|
- | 3.8.1 |
oslo.middleware
|
3.20.0 | 3.23.1 |