CVE-2025-48374: Project-Zot Zot

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. Prior to version 2.1.3 (corresponding to pseudoversion 1.4.4-0.20250522160828-8a99a3ed231f), when using Keycloak as an oidc provider, the clientsecret gets printed into the container stdout logs for an example at container startup. Version 2.1.3 (corresponding to pseudoversion 1.4.4-0.20250522160828-8a99a3ed231f) fixes the issue.

Affected products

  • Project-Zot Zot: before 1.4.4-0.20250522160828-8a99a3ed231f (fixed in 1.4.4-0.20250522160828-8a99a3ed231f)

Published 2025-05-22. Last modified 2026-06-17.