CVE-2023-3089
Ocp & fips mode
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
05 jul 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
Productos afectados
n/a · openshiftRed Hat · OpenShift ServerlessRed Hat · OpenShift Service Mesh 2.2.xRed Hat · OpenShift Service Mesh 2.3.xRed Hat · OpenShift Service Mesh 2.4Red Hat · Red Hat Advanced Cluster Management for Kubernetes 2Red Hat · Red Hat JBoss A-MQ StreamsRed Hat · Red Hat OpenShift Container Platform 3.11Red Hat · Red Hat OpenShift Container Platform 4Red Hat · Red Hat Openshift Data Foundation 4Red Hat · Red Hat Openshift sandboxed containersRed Hat · Red Hat OpenShift Virtualization 4¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →