CVE-2023-3089
Ocp & fips mode
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
05 Jul 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
Affected products
n/a · openshiftRed Hat · OpenShift ServerlessRed Hat · OpenShift Service Mesh 2.2.xRed Hat · OpenShift Service Mesh 2.3.xRed Hat · OpenShift Service Mesh 2.4Red Hat · Red Hat Advanced Cluster Management for Kubernetes 2Red Hat · Red Hat JBoss A-MQ StreamsRed Hat · Red Hat OpenShift Container Platform 3.11Red Hat · Red Hat OpenShift Container Platform 4Red Hat · Red Hat Openshift Data Foundation 4Red Hat · Red Hat Openshift sandboxed containersRed Hat · Red Hat OpenShift Virtualization 4Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →