Information Disclosure in OneLogin AD Connector Affected by Vulnerability
CVE-2025-34062
Key Information:
- Vendor
One Identity
- Vendor
- CVE Published:
- 1 July 2025
What is CVE-2025-34062?
An information disclosure vulnerability in OneLogin AD Connector allows attackers with access to a valid directory_token to extract sensitive information via the /api/adc/v4/configuration endpoint. This can lead to exposure of critical data, such as API keys, AWS IAM access and secret keys, as well as base64-encoded JWT signing keys associated with the tenant's SSO IdP configuration. The data can potentially be retrieved from host registry keys or inadequately secured logs, posing significant security concerns.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
OneLogin Active Directory Connector (ADC) 0 < 6.1.5
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
