CVE-2023-3089

EUVD-2023-43777
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
redhatCNA
7 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
Affected Products (NVD)
VendorProductVersion
redhatopenshift_container_platform
4.10
redhatopenshift_container_platform_for_linuxone
4.10
redhatopenshift_container_platform_for_linuxone
4.11
redhatopenshift_container_platform_for_power
4.10
redhatopenshift_container_platform_for_power
4.11
redhatopenshift_container_platform_ibm_z_systems
4.10
redhatopenshift_container_platform_ibm_z_systems
4.11
redhatopenshift_container_platform_for_arm64
4.10
redhatopenshift_container_platform_for_arm64
4.11
redhatopenshift_container_platform_for_arm64
4.12
redhatopenshift_container_platform_for_linuxone
4.12
redhatopenshift_container_platform_for_power
4.12
redhatopenshift_container_platform_ibm_z_systems
4.12
redhatopenshift_container_platform_for_arm64
4.12
𝑥
= Vulnerable software versions