Understanding of CVE-2023-48795 in OpenShift 4

Solution Verified - Updated -

Issue

  • SSH access to OpenShift nodes displays the use of vulnerable ciphers as mentioned on the CVE-2023-48795 page.
  • Vulnerable ciphers such as chacha20-poly1305@openssh.com / hmac-sha2-512-etm@openssh.com / hmac-sha2-256-etm@openssh.com / hmac-sha1-etm@openssh.com / hmac-md5-etm@openssh.com are in use in OpenShift clusters.

Environment

  • Red Hat OpenShift Container Platform (RHOCP)
    • 4
  • SSH Client and Server
  • Terrapin Attack

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content