A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216987.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-7680 A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216987.
Github GHSA Github GHSA GHSA-m7qp-cj9p-gj85 OpenShift OSIN vulnerable to Observable Timing Discrepancy
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2024-08-03T17:23:10.323Z

Reserved: 2022-12-28T16:49:47.686Z

Link: CVE-2021-4294

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-12-28T17:15:09.067

Modified: 2024-11-21T06:37:20.517

Link: CVE-2021-4294

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-12-28T00:00:00Z

Links: CVE-2021-4294 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses