CVE-2023-3089: Ocp & fips mode
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/openshiftto a version that resolves this vulnerability.Fixed in 4.12.0
Event History
Frequently Asked Questions
What is CVE-2023-3089?
CVE-2023-3089 is a compliance problem found in the Red Hat OpenShift Container Platform where not all cryptographic modules in use were FIPS-validated when FIPS mode was enabled.
What is the severity of CVE-2023-3089?
CVE-2023-3089 has a severity rating of high, with a CVSS score of 7.5.
Which software versions are affected by CVE-2023-3089?
The Red Hat OpenShift Container Platform versions 4.10, 4.11, and 4.12 are affected by CVE-2023-3089.
How can I fix CVE-2023-3089?
To fix CVE-2023-3089, update the affected Red Hat OpenShift Container Platform to version 4.12.0.
Where can I find more information about CVE-2023-3089?
You can find more information about CVE-2023-3089 on the Red Hat Bugzilla and Red Hat Customer Portal.