Understanding of CVE-2023-48795 in OpenShift 4
Issue
- SSH access to OpenShift nodes displays the use of vulnerable ciphers as mentioned on the CVE-2023-48795 page.
- Vulnerable ciphers such as
chacha20-poly1305@openssh.com/hmac-sha2-512-etm@openssh.com/hmac-sha2-256-etm@openssh.com/hmac-sha1-etm@openssh.com/hmac-md5-etm@openssh.comare in use in OpenShift clusters.
Environment
- Red Hat OpenShift Container Platform (RHOCP)
- 4
- SSH Client and Server
- Terrapin Attack
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.