A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Red Hat Enterprise Linux 10 | RedHat | podman-6:5.4.0-12.el10_0 | * |
Red Hat Enterprise Linux 8 | RedHat | container-tools:rhel8-8100020250625105344.afee755d | * |
Red Hat Enterprise Linux 9 | RedHat | podman-5:5.4.0-12.el9_6 | * |
Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | podman-4:4.9.4-18.el9_4.2 | * |
Red Hat OpenShift Container Platform 4.16 | RedHat | podman-4:4.9.4-16.rhaos4.16.el9 | * |
Red Hat OpenShift Container Platform 4.17 | RedHat | podman-5:5.2.2-8.rhaos4.17.el9 | * |
Red Hat OpenShift Container Platform 4.18 | RedHat | podman-5:5.2.2-9.rhaos4.18.el9 | * |
Red Hat OpenShift Container Platform 4.19 | RedHat | podman-5:5.4.0-6.rhaos4.19.el9 | * |