USN-3666-1: Oslo middleware vulnerability
31 May 2018
Applications using Oslo middleware could be made to expose sensitive information.
Releases
Packages
- python-oslo.middleware - WSGI middleware components for OpenStack
Details
Divya K Konoor discovered Oslo middleware was vulnerable to an information
disclosure. A local attacker could exploit this flaw to obtain sensitive
information from OpenStack component error logs.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
After a standard system update you need to restart OpenStack services to
make all the necessary changes.