CVE-2025-59363

In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created),
Configurations

No configuration.

History

No history.

Information

Published : 2025-09-14 05:15

Updated : 2025-09-15 15:21


NVD link : CVE-2025-59363

Mitre link : CVE-2025-59363

CVE.ORG link : CVE-2025-59363


JSON object : View

Products Affected

No product.

CWE
CWE-669

Incorrect Resource Transfer Between Spheres