Andrei Aaron

1 exploit Active since May 2025
CVE-2025-48374 WRITEUP MEDIUM WRITEUP
zot < 1.4.4-0.20250522160828-8a99a3ed231f - Sensitive Information Exposure in Logs via Keycloak OIDC Client Secret
zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. Prior to version 2.1.3 (corresponding to pseudoversion 1.4.4-0.20250522160828-8a99a3ed231f), when using Keycloak as an oidc provider, the clientsecret gets printed into the container stdout logs for an example at container startup. Version 2.1.3 (corresponding to pseudoversion 1.4.4-0.20250522160828-8a99a3ed231f) fixes the issue.