PT-2025-37401 · One Identity · Onelogin

Published

2025-09-14

·

Updated

2025-10-03

·

CVE-2025-59363

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions One Identity OneLogin versions prior to 2025.3.0
Description A security issue exists in One Identity OneLogin that allows attackers to potentially steal sensitive OpenID Connect (OIDC) application client secrets. This is possible through a request to the GET Apps API v2 endpoint, which incorrectly returns the OIDC client secret, even though it should only be returned during initial app creation. Successful exploitation could allow attackers to impersonate applications and gain unauthorized access to connected services. The issue is due to excessive data being returned by the application listing endpoint.
Recommendations Versions prior to 2025.3.0 should be updated to version 2025.3.0 or later. Consider rotating OIDC client secrets. Review logs for any suspicious activity. Restrict access to the GET Apps API v2 endpoint.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-59363

Affected Products

Onelogin