Moderate severityNVD Advisory· Published Dec 28, 2022· Updated Aug 3, 2024
OpenShift OSIN CheckClientSecret timing discrepancy
CVE-2021-4294
Description
A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216987.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/openshift/osinGo | < 1.0.2-0.20210113124101-8612686d6dda | 1.0.2-0.20210113124101-8612686d6dda |
Affected products
2Patches
Vulnerability mechanics
References
7- github.com/openshift/osin/commit/8612686d6dda34ae9ef6b5a974e4b7accb4fea29ghsapatchWEB
- github.com/advisories/GHSA-m7qp-cj9p-gj85ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-4294ghsaADVISORY
- github.com/openshift/osin/pull/200ghsaissue-trackingWEB
- pkg.go.dev/vuln/GO-2022-1201ghsaWEB
- vuldb.comghsasignaturepermissions-requiredWEB
- vuldb.comghsavdb-entrytechnical-descriptionWEB
News mentions
0No linked articles in our index yet.