CVE-2023-0296

Use of a Broken or Risky Cryptographic Algorithm in go/github.com/openshift/builder/pkg/build/builder

Identifiers

CVE-2023-0296

Package Slug

go/github.com/openshift/builder/pkg/build/builder

Vulnerability

Use of a Broken or Risky Cryptographic Algorithm

Description

The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in the etcd components, to enable periodic health checks from kubelet, it was necessary to open up a new port (9979) on etcd grpc-proxy, hence this port might be considered as still vulnerable to the same type of vulnerability. The health checks on etcd grpc-proxy do not contain sensitive data (only metrics data), therefore the potential impact related to this vulnerability is minimal. The CVE-2023-0296 has been assigned to this issue to track the permanent fix in the etcd component.

Affected Versions

Version 4.11

Solution

Unfortunately, there is no solution available yet.

Last Modified

2023-01-27

source