An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attacker with access to a valid directory_token—which may be retrievable from host registry keys or improperly secured logs—can retrieve a plaintext response disclosing sensitive credentials. These may include an API key, AWS IAM access and secret keys, and a base64-encoded JWT signing key used in the tenant’s SSO IdP configuration.
                
            CVSS
                No CVSS.
References
                    Configurations
                    No configuration.
History
                    03 Jul 2025, 15:14
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
01 Jul 2025, 15:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-07-01 15:15
Updated : 2025-07-03 15:14
NVD link : CVE-2025-34062
Mitre link : CVE-2025-34062
CVE.ORG link : CVE-2025-34062
JSON object : View
Products Affected
                No product.
