PT-2025-37401 · One Identity · Onelogin
Published
2025-09-14
·
Updated
2025-10-03
·
CVE-2025-59363
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
One Identity OneLogin versions prior to 2025.3.0
Description
A security issue exists in One Identity OneLogin that allows attackers to potentially steal sensitive OpenID Connect (OIDC) application client secrets. This is possible through a request to the GET Apps API v2 endpoint, which incorrectly returns the OIDC client secret, even though it should only be returned during initial app creation. Successful exploitation could allow attackers to impersonate applications and gain unauthorized access to connected services. The issue is due to excessive data being returned by the application listing endpoint.
Recommendations
Versions prior to 2025.3.0 should be updated to version 2025.3.0 or later.
Consider rotating OIDC client secrets.
Review logs for any suspicious activity.
Restrict access to the GET Apps API v2 endpoint.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Onelogin