Описание
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.
Отчет
https://access.redhat.com/security/vulnerabilities/RHSB-2023-001 The static scanning tool (to verify your system is once again compliant with FIPS) is available here https://github.com/openshift/check-payload
Меры по смягчению последствий
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected packages as soon as possible.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | openshift | Not affected | ||
| DEVWORKSPACE-1.0-RHEL-8 | devworkspace/devworkspace-operator-bundle | Fixed | RHSA-2023:4276 | 25.07.2023 |
| DEVWORKSPACE-1.0-RHEL-8 | devworkspace/devworkspace-project-clone-rhel8 | Fixed | RHSA-2023:4276 | 25.07.2023 |
| DEVWORKSPACE-1.0-RHEL-8 | devworkspace/devworkspace-rhel8-operator | Fixed | RHSA-2023:4276 | 25.07.2023 |
| Multicluster Engine for Kubernetes | multicluster-engine-agent-service-container | Fixed | RHSA-2023:4972 | 05.09.2023 |
| Multicluster Engine for Kubernetes | multicluster-engine-apiserver-network-proxy-container | Fixed | RHSA-2023:4972 | 05.09.2023 |
| Multicluster Engine for Kubernetes | multicluster-engine-assisted-image-service-container | Fixed | RHSA-2023:4972 | 05.09.2023 |
| Multicluster Engine for Kubernetes | multicluster-engine-assisted-installer-agent-container | Fixed | RHSA-2023:4972 | 05.09.2023 |
| Multicluster Engine for Kubernetes | multicluster-engine-assisted-installer-container | Fixed | RHSA-2023:4972 | 05.09.2023 |
| Multicluster Engine for Kubernetes | multicluster-engine-assisted-installer-reporter-container | Fixed | RHSA-2023:4972 | 05.09.2023 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.
EPSS
6.5 Medium
CVSS3