CVE-2023-3089
05.07.2023, 13:15
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | openshift_container_platform | 4.10 |
redhat | openshift_container_platform_for_linuxone | 4.10 |
redhat | openshift_container_platform_for_linuxone | 4.11 |
redhat | openshift_container_platform_for_power | 4.10 |
redhat | openshift_container_platform_for_power | 4.11 |
redhat | openshift_container_platform_ibm_z_systems | 4.10 |
redhat | openshift_container_platform_ibm_z_systems | 4.11 |
redhat | openshift_container_platform_for_arm64 | 4.10 |
redhat | openshift_container_platform_for_arm64 | 4.11 |
redhat | openshift_container_platform_for_arm64 | 4.12 |
redhat | openshift_container_platform_for_linuxone | 4.12 |
redhat | openshift_container_platform_for_power | 4.12 |
redhat | openshift_container_platform_ibm_z_systems | 4.12 |
redhat | openshift_container_platform_for_arm64 | 4.12 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-693 - Protection Mechanism FailureThe product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
- CWE-521 - Weak Password RequirementsThe product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.