CVE-2021-4294
published 2022-12-28CVE-2021-4294: A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The…
PriorityP429medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.68%
48.1th percentile
A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216987.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | openshift_osin | >= 0 < 1.0.2-0.20210113124101-8612686d6dda | 1.0.2-0.20210113124101-8612686d6dda |
| openshift | osin | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_osin | — | — |
| redhat | openshift_osin | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Timing attack in github.com/openshift/osin
osv·2023-01-03
CVE-2021-4294 Timing attack in github.com/openshift/osin
Timing attack in github.com/openshift/osin
Client secret checks are vulnerable to timing attacks, which could permit an attacker to determine client secrets.
GHSA
OpenShift OSIN vulnerable to Observable Timing Discrepancy
ghsa·2022-12-28
CVE-2021-4294 [MEDIUM] CWE-203 OpenShift OSIN vulnerable to Observable Timing Discrepancy
OpenShift OSIN vulnerable to Observable Timing Discrepancy
A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function `ClientSecretMatches/CheckClientSecret`. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216987.
OSV
OpenShift OSIN vulnerable to Observable Timing Discrepancy
osv·2022-12-28
CVE-2021-4294 [MEDIUM] OpenShift OSIN vulnerable to Observable Timing Discrepancy
OpenShift OSIN vulnerable to Observable Timing Discrepancy
A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function `ClientSecretMatches/CheckClientSecret`. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216987.
Red Hat
kernel: io_uring: fix shared sqpoll cancellation hangs
vendor_redhat·2024-02-27·CVSS 5.5
CVE-2021-46942 [MEDIUM] CWE-20 kernel: io_uring: fix shared sqpoll cancellation hangs
kernel: io_uring: fix shared sqpoll cancellation hangs
In the Linux kernel, the following vulnerability has been resolved:
io_uring: fix shared sqpoll cancellation hangs
[ 736.982891] INFO: task iou-sqp-4294:4295 blocked for more than 122 seconds.
[ 736.982897] Call Trace:
[ 736.982901] schedule+0x68/0xe0
[ 736.982903] io_uring_cancel_sqpoll+0xdb/0x110
[ 736.982908] io_sqpoll_cancel_cb+0x24/0x30
[ 736.982911] io_run_task_work_head+0x28/0x50
[ 736.982913] io_sq_thread+0x4e3/0x720
We call io_uring_cancel_sqpoll() one by one for each ctx either in
sq_thread() itself or via task works, and it's intended to cancel all
requests of a specified context. However the function uses per-task
counters to track the number of inflight requests, so it counts more
requests than available via currect io_ur
Red Hat
osin: manipulation of the argument secret leads to observable timing discrepancy
vendor_redhat·2022-12-28·CVSS 2.6
CVE-2021-4294 [LOW] CWE-208 osin: manipulation of the argument secret leads to observable timing discrepancy
osin: manipulation of the argument secret leads to observable timing discrepancy
A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216987.
A vulnerability was found in OpenShift OSIN. This issue affects the ClientSecretMatches/CheckClientSecret function, where the manipulation of the argument secret leads to an observable timing discrepancy.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/openshift/osin/commit/8612686d6dda34ae9ef6b5a974e4b7accb4fea29https://github.com/openshift/osin/pull/200https://vuldb.com/?ctiid.216987https://vuldb.com/?id.216987https://github.com/openshift/osin/commit/8612686d6dda34ae9ef6b5a974e4b7accb4fea29https://github.com/openshift/osin/pull/200https://vuldb.com/?ctiid.216987https://vuldb.com/?id.216987
2022-12-28
Published