CVE-2025-59363
Severity CVSS v4.0:
Pending analysis
Type:
CWE-669
Incorrect Resource Transfer Between Spheres
Publication date:
14/09/2025
Last modified:
15/09/2025
Description
In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created),
Impact
Base Score 3.x
7.70
Severity 3.x
HIGH



