CVE-2025-34062

An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attacker with access to a valid directory_token—which may be retrievable from host registry keys or improperly secured logs—can retrieve a plaintext response disclosing sensitive credentials. These may include an API key, AWS IAM access and secret keys, and a base64-encoded JWT signing key used in the tenant’s SSO IdP configuration.
CVSS

No CVSS.

Configurations

No configuration.

History

03 Jul 2025, 15:14

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-01 15:15

Updated : 2025-07-03 15:14


NVD link : CVE-2025-34062

Mitre link : CVE-2025-34062

CVE.ORG link : CVE-2025-34062


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-522

Insufficiently Protected Credentials