PT-2022-11745 · Red Hat · Openshift Osin
Govulnbot
·
Published
2022-12-28
·
Updated
2024-05-17
·
CVE-2021-4294
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenShift OSIN (affected versions not specified)
Description
A vulnerability was found in OpenShift OSIN, classified as problematic. It affects the function
ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy, making it vulnerable to timing attacks. This could permit an attacker to determine client secrets.Recommendations
To fix this issue, it is recommended to apply a patch. As a temporary workaround, consider restricting access to the
ClientSecretMatches/CheckClientSecret function until a patch is available. Avoid using the secret argument in the affected function to minimize the risk of exploitation.Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openshift Osin