Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-3089

Опубликовано: 05 июл. 2023
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.

Отчет

https://access.redhat.com/security/vulnerabilities/RHSB-2023-001 The static scanning tool (to verify your system is once again compliant with FIPS) is available here https://github.com/openshift/check-payload

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected packages as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel9Affected
Red Hat OpenShift Container Platform 3.11openshiftNot affected
DEVWORKSPACE-1.0-RHEL-8devworkspace/devworkspace-operator-bundleFixedRHSA-2023:427625.07.2023
DEVWORKSPACE-1.0-RHEL-8devworkspace/devworkspace-project-clone-rhel8FixedRHSA-2023:427625.07.2023
DEVWORKSPACE-1.0-RHEL-8devworkspace/devworkspace-rhel8-operatorFixedRHSA-2023:427625.07.2023
Openshift Serverless 1 on RHEL 8openshift-serverless-clientsFixedRHSA-2023:447103.08.2023
OSE-OSC-1.4-RHEL-9openshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9FixedRHSA-2023:429027.07.2023
OSE-OSC-1.4-RHEL-9openshift-sandboxed-containers/osc-cloud-api-adaptor-webhook-rhel9FixedRHSA-2023:429027.07.2023
OSE-OSC-1.4-RHEL-9openshift-sandboxed-containers/osc-monitor-rhel9FixedRHSA-2023:429027.07.2023
OSE-OSC-1.4-RHEL-9openshift-sandboxed-containers/osc-must-gather-rhel9FixedRHSA-2023:429027.07.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-327

EPSS

Процентиль: 43%
0.0052
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7
nvd
около 3 лет назад

A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.

CVSS3: 7
github
около 3 лет назад

A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.

EPSS

Процентиль: 43%
0.0052
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2023-3089