In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created),
Metrics
Affected Vendors & Products
References
History
Mon, 15 Sep 2025 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Oneidentity
Oneidentity onelogin |
|
Vendors & Products |
Oneidentity
Oneidentity onelogin |
Sun, 14 Sep 2025 05:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created), | |
Weaknesses | CWE-669 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-09-14T00:00:00.000Z
Updated: 2025-09-14T04:51:44.158Z
Reserved: 2025-09-14T00:00:00.000Z
Link: CVE-2025-59363

No data.

Status : Received
Published: 2025-09-14T05:15:31.680
Modified: 2025-09-14T05:15:31.680
Link: CVE-2025-59363

No data.