CVE-2025-34062 - CVE House
Back to Database
Status published Medium CVE-2025-34062

OneLogin AD Connector API Credential and Signing Key Exposure

Vulnerability Description

An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attacker with access to a valid directory_token—which may be retrievable from host registry keys or improperly secured logs—can retrieve a plaintext response disclosing sensitive credentials. These may include an API key, AWS IAM access and secret keys, and a base64-encoded JWT signing key used in the tenant’s SSO IdP configuration.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34062

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • SpecterOps

Affected Vendor

One Identity

View all reports →

Affected Software

OneLogin Active Directory Connector (ADC)
Vulnerable Versions:
0

Timeline

Official Publish: July 1st, 2025
Last Modified: July 1st, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)