VDB
Sign up
—

GO-2022-1201

Timing attack in github.com/openshift/osin

Quick fix

GO-2022-1201 — github.com/openshift/osin: upgrade to the fixed version with the command below.

go get github.com/openshift/osin@v1.0.2-0.20210113124101-8612686d6dda

Details

Client secret checks are vulnerable to timing attacks, which could permit an attacker to determine client secrets.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/openshift/osin
Introduced in: 0Fixed in: 1.0.2-0.20210113124101-8612686d6dda
Fixgo get github.com/openshift/osin@v1.0.2-0.20210113124101-8612686d6dda

References