Executive brief
Red Hat Quay is a platform for managing and storing container images. A security flaw in its configuration tool causes sensitive GitLab login credentials to be sent in a way that makes them visible in system logs. If an unauthorized person gains access to these logs, they could steal the credentials and potentially access the linked GitLab account.
Technical details
A flaw exists in the Quay config-tool's GitLab OAuth validator within 'pkg/lib/shared/validators.go'. When performing validation, the tool transmits 'client_id' and 'client_secret' as plaintext URL query parameters during POST requests to the GitLab endpoint instead of using secure HTTP headers. This behavior (CWE-598) results in sensitive credentials being recorded in server access logs, reverse proxy logs, WAF logs, and monitoring traces. An attacker with high privileges or access to these logging systems could retrieve the credentials to facilitate unauthorized information disclosure. The GitHub OAuth validator is reportedly unaffected as it correctly utilizes HTTP Basic Auth headers.
Affected products
- Red Hat Quay config-tool unspecified
Timeline
- 2026-05-29: disclosed: Initial disclosure and NVD publication