CVE-2021-4294
Red Hat Enterprise Linux CoreOS (RHCOS) vulnerability analysis and mitigation

Overview

A vulnerability was discovered in OpenShift OSIN affecting the ClientSecretMatches function, identified as CVE-2021-4294. The issue relates to the manipulation of argument secrets leading to observable timing discrepancies, which could potentially be exploited through timing attacks. The vulnerability was addressed in OpenShift Container Platform updates (Red Hat Advisory).

Technical details

The vulnerability stems from the use of non-constant time comparison operations when checking client secrets in the OSIN authentication system. The issue was fixed by implementing constant-time comparisons using the crypto/subtle package to prevent potential timing attacks. The fix involved modifying the ClientSecretMatches function to use subtle.ConstantTimeCompare instead of direct string comparison (GitHub Commit). The vulnerability has been assigned a CVSS v3 score of 5.9, indicating moderate severity (Red Hat CVE).

Impact

The vulnerability could potentially allow attackers to perform timing attacks against the authentication system, potentially leading to the extraction of sensitive information about client secrets through careful measurement of response times in secret comparison operations (GitHub PR).

Mitigation and workarounds

The vulnerability has been fixed in recent versions of OpenShift Container Platform through security updates. Users are advised to upgrade to the latest version of affected OpenShift Container Platform releases. The fix implements constant-time comparisons for client secrets using the crypto/subtle package, effectively preventing timing-based attacks (Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related Red Hat Enterprise Linux CoreOS (RHCOS) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-11561HIGH8.8
  • Rocky LinuxRocky Linux
  • libsss_nss_idmap
NoYesOct 09, 2025
CVE-2025-52565HIGH8.4
  • cAdvisorcAdvisor
  • kernel-64k-debug
NoYesNov 06, 2025
CVE-2025-4953HIGH7.4
  • PodmanPodman
  • container-tools:rhel8::python3-podman
NoYesSep 16, 2025
CVE-2025-52881HIGH7.3
  • cAdvisorcAdvisor
  • podman-plugins
NoYesNov 06, 2025
CVE-2025-31133HIGH7.3
  • cAdvisorcAdvisor
  • kernel-zfcpdump-modules-partner
NoYesNov 06, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management