PT-2022-11745 · Red Hat · Openshift Osin

Govulnbot

·

Published

2022-12-28

·

Updated

2024-05-17

·

CVE-2021-4294

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenShift OSIN (affected versions not specified)
Description A vulnerability was found in OpenShift OSIN, classified as problematic. It affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy, making it vulnerable to timing attacks. This could permit an attacker to determine client secrets.
Recommendations To fix this issue, it is recommended to apply a patch. As a temporary workaround, consider restricting access to the ClientSecretMatches/CheckClientSecret function until a patch is available. Avoid using the secret argument in the affected function to minimize the risk of exploitation.

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2021-4294
GHSA-M7QP-CJ9P-GJ85
GO-2022-1201

Affected Products

Openshift Osin