CVE-2025-6032

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
CVSS

No CVSS.

Configurations

No configuration.

History

30 Jul 2025, 23:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:11677 -

30 Jul 2025, 14:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:11681 -

22 Jul 2025, 20:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:11363 -

09 Jul 2025, 08:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:10295 -

09 Jul 2025, 03:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:10668 -

08 Jul 2025, 03:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:10551 -
  • () https://access.redhat.com/errata/RHSA-2025:10550 -
  • () https://access.redhat.com/errata/RHSA-2025:10549 -

02 Jul 2025, 08:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:9766 -
  • () https://access.redhat.com/errata/RHSA-2025:9726 -

01 Jul 2025, 08:15

Type Values Removed Values Added
CWE CWE-295
References
  • () https://access.redhat.com/errata/RHSA-2025:9751 -
CVSS v2 : unknown
v3 : 8.3
v2 : unknown
v3 : unknown

24 Jun 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-24 14:15

Updated : 2025-07-30 23:15


NVD link : CVE-2025-6032

Mitre link : CVE-2025-6032


JSON object : View

Products Affected

No product.

CWE

No CWE.