OneLogin AD Connector Log S3 Bucket Hijack Leading to Cross-Tenant Data Leakage
Vulnerability Description
A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket (onelogin-adc-logs-production) without validating bucket ownership. An attacker who registers this unclaimed bucket can begin receiving log files from other OneLogin tenants. These logs may contain sensitive data such as directory tokens, user metadata, and environment configuration. This enables cross-tenant leakage of secrets, potentially allowing JWT signing key recovery and user impersonation.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34064
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- SpecterOps
References
More from One Identity
View All →Affected Vendor
One Identity
View all reports →