CVE-2025-52924: One Identity Onelogin
Medium severity, CVSS 4.0. EPSS: 0.3% chance of exploitation in the next 30 days.
In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untrusted X-RequestId HTTP request header.
Affected products
- One Identity Onelogin: before 2025.2.0 (fixed in 2025.2.0)
Published 2025-07-19. Last modified 2026-06-17.