CVE-2025-59363
14.09.2025, 05:15
In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created),Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.