OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys
ID: 9eb56791-8ed5-52b8-9f6f-82c1fba50d36
STIX ID: report--9eb56791-8ed5-52b8-9f6f-82c1fba50d36
Feed Name: SpecterOps Blog
A security researcher discovered that OneLogin's AD Connector exposed sensitive configuration data — including directory tokens, an API key, a base64 signing key used to sign JWTs, and AWS credentials — via an ADC configuration API and customer logs sent to an unclaimed S3 bucket. Using those artifacts the researcher was able to generate valid JWTs to impersonate arbitrary users in affected OneLogin tenants and access assigned applications; the researcher claimed the S3 bucket, confirmed another customer's data was leaking there, and engaged in coordinated disclosure with OneLogin while providing defensive guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
