{"id":"GHSA-m7qp-cj9p-gj85","summary":"OpenShift OSIN vulnerable to Observable Timing Discrepancy","details":"A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function `ClientSecretMatches/CheckClientSecret`. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216987.","aliases":["CVE-2021-4294","GO-2022-1201"],"modified":"2024-03-01T14:23:07Z","published":"2022-12-28T18:30:20Z","database_specific":{"nvd_published_at":"2022-12-28T17:15:00Z","cwe_ids":["CWE-203","CWE-208"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-01-09T21:50:04Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-4294"},{"type":"WEB","url":"https://github.com/openshift/osin/pull/200"},{"type":"WEB","url":"https://github.com/openshift/osin/commit/8612686d6dda34ae9ef6b5a974e4b7accb4fea29"},{"type":"PACKAGE","url":"https://github.com/openshift/osin"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2022-1201"},{"type":"WEB","url":"https://vuldb.com/?ctiid.216987"},{"type":"WEB","url":"https://vuldb.com/?id.216987"}],"affected":[{"package":{"name":"github.com/openshift/osin","ecosystem":"Go","purl":"pkg:golang/github.com/openshift/osin"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.2-0.20210113124101-8612686d6dda"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/12/GHSA-m7qp-cj9p-gj85/GHSA-m7qp-cj9p-gj85.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}