Low severity2.6NVD Advisory· Published Dec 28, 2022· Updated Jun 17, 2026
CVE-2021-4294
CVE-2021-4294
Description
A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216987.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/openshift/osinGo | < 1.0.2-0.20210113124101-8612686d6dda | 1.0.2-0.20210113124101-8612686d6dda |
Affected products
5- cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_osin:1.0.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:openshift_osin:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_osin:1.0.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
7- github.com/openshift/osin/commit/8612686d6dda34ae9ef6b5a974e4b7accb4fea29nvdPatchWEB
- github.com/advisories/GHSA-m7qp-cj9p-gj85ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-4294ghsaADVISORY
- github.com/openshift/osin/pull/200nvdIssue TrackingWEB
- pkg.go.dev/vuln/GO-2022-1201ghsaWEB
- vuldb.comnvdPermissions RequiredWEB
- vuldb.comnvdPermissions RequiredWEB
News mentions
0No linked articles in our index yet.