python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "3.8.0-2ubuntu1", "binary_name": "python-oslo-middleware" }, { "binary_version": "3.8.0-2ubuntu1", "binary_name": "python-oslo-middleware-doc" }, { "binary_version": "3.8.0-2ubuntu1", "binary_name": "python-oslo.middleware" }, { "binary_version": "3.8.0-2ubuntu1", "binary_name": "python-oslo.middleware-doc" }, { "binary_version": "3.8.0-2ubuntu1", "binary_name": "python3-oslo-middleware" }, { "binary_version": "3.8.0-2ubuntu1", "binary_name": "python3-oslo.middleware" } ] }