Description
An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attacker with access to a valid directory_token—which may be retrievable from host registry keys or improperly secured logs—can retrieve a plaintext response disclosing sensitive credentials. These may include an API key, AWS IAM access and secret keys, and a base64-encoded JWT signing key used in the tenant’s SSO IdP configuration.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CWE-522 Insufficiently Protected Credentials
Product status
Any version before 6.1.5
Credits
SpecterOps
References
support.onelogin.com/product-notification/noti-00001768
specterops.io/...nant-to-compromising-customer-signing-keys/
vulncheck.com/...es/onelogin-ad-connector-account-compromise