zot logs secrets
GHSA-c37v-3c8w-crq8 · CVE-2025-48374 · GO-2025-3705
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Summary
When using Keycloak as an oidc provider, the clientsecret gets printed into the container stdout logs for an example at container startup.
Details
Container Image (15.04.2025): ghcr.io/project-zot/zot-linux-amd64:latest
Here is an example how the configuration can look which causes the above stated problem:
http: address: "0.0.0.0" port: 5000 externalUrl: "https://zot.example.com" auth: { failDelay: 1, openid: { providers: { oidc: { name: "Keycloak", clientid: "zot-client-id", clientsecret: fsdfkmmiwljasdklfsjaskldjfkljewijrf234i52k3j45l, keypath: "", issuer: "https://keycloak.example.com/realms/example", scopes: ["openid"] } } } }
PoC
Set up a blank new zot k8s deployment with the code snippet above.
Impact
exposure of secrets, on configuring a oidc provider
References
- WEB https://github.com/project-zot/zot/security/advisories/GHSA-c37v-3c8w-crq8
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-48374
- WEB https://github.com/project-zot/zot/commit/8a99a3ed231fdcd8467e986182b4705342b6a15e
- PACKAGE https://github.com/project-zot/zot
- WEB https://pkg.go.dev/vuln/GO-2025-3705
Ready to move
Start Securing
Free, no credit card | First findings in minutes