CVE-2025-59363 - OneLogin OneLogin OIDC Client Secret Disclosure
CVE ID : CVE-2025-59363
Published : Sept. 14, 2025, 5:15 a.m. | 3 hours, 54 minutes ago
Description : In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created),
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 14, 2025, 5:15 a.m. | 3 hours, 54 minutes ago
Description : In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created),
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...