CVE-2023-3089

A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
redhatCNA
7 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 10%
VendorProductVersion
redhatopenshift_container_platform
4.10
redhatopenshift_container_platform_for_linuxone
4.10
redhatopenshift_container_platform_for_linuxone
4.11
redhatopenshift_container_platform_for_power
4.10
redhatopenshift_container_platform_for_power
4.11
redhatopenshift_container_platform_ibm_z_systems
4.10
redhatopenshift_container_platform_ibm_z_systems
4.11
redhatopenshift_container_platform_for_arm64
4.10
redhatopenshift_container_platform_for_arm64
4.11
redhatopenshift_container_platform_for_arm64
4.12
redhatopenshift_container_platform_for_linuxone
4.12
redhatopenshift_container_platform_for_power
4.12
redhatopenshift_container_platform_ibm_z_systems
4.12
redhatopenshift_container_platform_for_arm64
4.12
𝑥
= Vulnerable software versions