CVE Vulnerabilities

CVE-2025-52925

Transmission of Private Resources into a New Sphere ('Resource Leak')

Published: Jul 02, 2025 | Modified: Jul 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812.

Weakness

The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.

References