CVE-2025-59363

In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created),
Configurations

No configuration.

History

14 Sep 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-14 05:15

Updated : 2025-09-15 15:21


NVD link : CVE-2025-59363

Mitre link : CVE-2025-59363

CVE.ORG link : CVE-2025-59363


JSON object : View

Products Affected

No product.

CWE
CWE-669

Incorrect Resource Transfer Between Spheres