We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attacker with access to a valid directory_token—which may be retrievable from host registry keys or improperly secured logs—can retrieve a plaintext response disclosing sensitive credentials. These may include an API key, AWS IAM access and secret keys, and a base64-encoded JWT signing key used in the tenant’s SSO IdP configuration.
Reserved 2025-04-15 | Published 2025-07-01 | Updated 2025-07-01 | Assigner VulnCheckCWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CWE-522 Insufficiently Protected Credentials
SpecterOps
support.onelogin.com/product-notification/noti-00001768
specterops.io/...nant-to-compromising-customer-signing-keys/
vulncheck.com/...es/onelogin-ad-connector-account-compromise
Support options