Bug 2156871 (CVE-2021-4294) - CVE-2021-4294 osin: manipulation of the argument secret leads to observable timing discrepancy
Summary: CVE-2021-4294 osin: manipulation of the argument secret leads to observable t...
Keywords:
Status: NEW
Alias: CVE-2021-4294
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2156872
TreeView+ depends on / blocked
 
Reported: 2022-12-29 04:28 UTC by Avinash Hanwate
Modified: 2023-07-07 08:31 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in OpenShift OSIN. This issue affects the ClientSecretMatches/CheckClientSecret function, where the manipulation of the argument secret leads to an observable timing discrepancy.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Avinash Hanwate 2022-12-29 04:28:16 UTC
A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216987.

https://vuldb.com/?id.216987
https://github.com/openshift/osin/commit/8612686d6dda34ae9ef6b5a974e4b7accb4fea29
https://github.com/openshift/osin/pull/200
https://vuldb.com/?ctiid.216987

Comment 3 sakshi 2023-02-06 05:43:38 UTC
Hi Team, 


The customer is using openshift Version 4.10.20 and is affected by this vulnerability and wants to know when this will be fixed.


Thanks
Sakshi


Note You need to log in before you can comment on or make changes to this bug.