When using Keycloak as an oidc provider, the clientsecret gets printed into the container stdout logs for an example at container startup.
Container Image (15.04.2025): ghcr.io/project-zot/zot-linux-amd64:latest Here is an example how the configuration can look which causes the above stated problem:
http: address: "0.0.0.0" port: 5000 externalUrl: "https://zot.example.com" auth: { failDelay: 1, openid: { providers: { oidc: { name: "Keycloak", clientid: "zot-client-id", clientsecret: fsdfkmmiwljasdklfsjaskldjfkljewijrf234i52k3j45l, keypath: "", issuer: "https://keycloak.example.com/realms/example", scopes: ["openid"] } } } }
Set up a blank new zot k8s deployment with the code snippet above.
exposure of secrets, on configuring a oidc provider
{
"cwe_ids": [
"CWE-532"
],
"github_reviewed": true,
"github_reviewed_at": "2025-05-22T20:33:39Z",
"nvd_published_at": "2025-05-22T21:15:37Z",
"severity": "MODERATE"
}