Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29110 | In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created), |
Mon, 15 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oneidentity
Oneidentity onelogin |
|
| Vendors & Products |
Oneidentity
Oneidentity onelogin |
Sun, 14 Sep 2025 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created), | |
| Weaknesses | CWE-669 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-15T15:57:12.079Z
Reserved: 2025-09-14T00:00:00.000Z
Link: CVE-2025-59363
Updated: 2025-09-15T15:57:08.480Z
Status : Deferred
Published: 2025-09-14T05:15:31.680
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-59363
No data.
OpenCVE Enrichment
Updated: 2025-09-15T10:43:27Z
EUVD