VYPR

Go modules package

github.com/openshift/osin

pkg:golang/github.com/openshift/osin

Vulnerabilities (1)

  • CVE-2021-4294Dec 28, 2022
    affected < 1.0.2-0.20210113124101-8612686d6ddafixed 1.0.2-0.20210113124101-8612686d6dda

    A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974