CVE-2025-34062: OneLogin AD Connector API Credential and Signing Key Exposure
An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attacker with access to a valid directorytoken—which may be retrievable from host registry keys or improperly secured logs—can retrieve a plaintext response disclosing sensitive credentials. These may include an API key, AWS IAM access and secret keys, and a base64-encoded JWT signing key used in the tenant’s SSO IdP configuration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34062?
CVE-2025-34062 is considered a medium-severity information disclosure vulnerability.
How do I fix CVE-2025-34062?
To fix CVE-2025-34062, upgrade OneLogin AD Connector to version 6.1.5 or later.
What is the attack vector for CVE-2025-34062?
The attack vector for CVE-2025-34062 requires an attacker to have access to a valid directory_token.
What types of data are exposed due to CVE-2025-34062?
CVE-2025-34062 allows attackers to retrieve sensitive configuration data from the /api/adc/v4/configuration endpoint.
Which versions of OneLogin AD Connector are affected by CVE-2025-34062?
CVE-2025-34062 affects all versions of OneLogin AD Connector prior to 6.1.5.