Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-65gg-3w2w-hr4h

Опубликовано: 25 июн. 2025
Источник: github
Github: Прошло ревью
CVSS3: 8.3

Описание

Podman Improper Certificate Validation; machine missing TLS verification

Impact

The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry (which it does by default since 5.0.0) allowing a possible Man In The Middle attack.

Patches

https://github.com/containers/podman/commit/726b506acc8a00d99f1a3a1357ecf619a1f798c3 Fixed in v5.5.2

Workarounds

Download the disk image manually via some other tool that verifies the TLS connection. Then pass the local image as file path (podman machine init --image ./somepath)

Пакеты

Наименование

github.com/containers/podman/v4

go
Затронутые версииВерсия исправления

>= 4.8.0, <= 4.9.5

Отсутствует

Наименование

github.com/containers/podman/v5

go
Затронутые версииВерсия исправления

< 5.5.2

5.5.2

EPSS

Процентиль: 8%
0.00034
Низкий

8.3 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 8.3
ubuntu
28 дней назад

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

CVSS3: 8.3
redhat
28 дней назад

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

CVSS3: 8.3
nvd
28 дней назад

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

CVSS3: 8.3
debian
28 дней назад

A flaw was found in Podman. The podman machine init command fails to v ...

oracle-oval
14 дней назад

ELSA-2025-10551: container-tools:rhel8 security update (IMPORTANT)

EPSS

Процентиль: 8%
0.00034
Низкий

8.3 High

CVSS3

Дефекты

CWE-295