cbcvebase.
CVE-2025-64131
published 2025-10-29

CVE-2025-64131: Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML…

high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a user's web browser and Jenkins to replay those requests, authenticating to Jenkins as that user.

Affected

16 ranges
VendorProductVersion rangeFixed in
jenkinsazure_cli_plugin
jenkinsbyteguard_build_actions_plugin
jenkinscurseforge_publisher_plugin
jenkinseggplant_runner_plugin
jenkinsextensible_choice_parameter_plugin
jenkinsjdepend_maven_plugin
jenkinsjdepend_plugin
jenkinsmcp_server_plugin
jenkinsnexus_task_runner_plugin
jenkinsopenshift_pipeline_plugin
jenkinspublish_to_bitbucket_plugin
jenkinssaml< 4.583.585.v22ccc1139f554.583.585.v22ccc1139f55
jenkinssaml_plugin
jenkinsstart_windocks_containers_plugin
jenkinsthemis_plugin
jenkins_projectjenkins_saml_plugin<= 4.583.vc68232f7018a_