OpenShift OSIN vulnerable to Observable Timing Discrepancy
Moderate severity
GitHub Reviewed
Published
Dec 28, 2022
to the GitHub Advisory Database
•
Updated Mar 1, 2024
Package
Affected versions
< 1.0.2-0.20210113124101-8612686d6dda
Patched versions
1.0.2-0.20210113124101-8612686d6dda
Description
Published by the National Vulnerability Database
Dec 28, 2022
Published to the GitHub Advisory Database
Dec 28, 2022
Reviewed
Jan 9, 2023
Last updated
Mar 1, 2024
A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function
ClientSecretMatches/CheckClientSecret
. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216987.References