REDHAT-BUG-2483168: Low severity Quay Quay config-tool vulnerability

Published May 29, 2026
·
Updated

The Quay config-tool's GitLab OAuth validator in pkg/lib/shared/validators.go (line 804) places clientid and clientsecret as plaintext URL querystring parameters when making POST requests to the configured GitLab endpoint. This causes credentials to leak into server access logs, reverse proxy logs, WAF logs, CDN logs, and OpenTelemetry traces even when the endpoint is the legitimate gitlab.com. The GitHub OAuth validator correctly uses HTTP Basic Auth headers and is not affected.

Affected Software

1 affected component
Quay Quay config-tool

Event History

May 29, 2026
Data Sourced
via Red Hat·08:57 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2483168?

The severity of REDHAT-BUG-2483168 is rated as low.

2

What does REDHAT-BUG-2483168 describe?

REDHAT-BUG-2483168 describes a vulnerability in the Quay config-tool where client_id and client_secret are sent as plaintext in URL query strings.

3

How does REDHAT-BUG-2483168 affect security?

REDHAT-BUG-2483168 affects security by leaking sensitive credentials into server and reverse proxy access logs.

4

What software is affected by REDHAT-BUG-2483168?

The affected software by REDHAT-BUG-2483168 is Quay and its config-tool.

5

How can I mitigate the risk associated with REDHAT-BUG-2483168?

To mitigate the risk of REDHAT-BUG-2483168, avoid using plaintext client_id and client_secret in query strings and adopt secure communication methods.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203