Jenkins Project Jenkins Saml Plugin vulnerabilities
2 known vulnerabilities affecting jenkins_project/jenkins_saml_plugin.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2025-64131HIGHCVSS 7.5≤ 4.583.vc68232f7018a_2025-10-29
CVE-2025-64131 [HIGH] CWE-294 CVE-2025-64131: Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing att
Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a user's web browser and Jenkins to replay those requests, authenticating to Jenkins as that user.
cvelistv5nvd
CVE-2021-21678HIGHCVSS 8.8≥ 1.1.3, < unspecified≥ unspecified, ≤ 2.0.72021-08-31
CVE-2021-21678 [HIGH] CWE-352 CVE-2021-21678: Jenkins SAML Plugin 2.0.7 and earlier allows attackers to craft URLs that would bypass the CSRF prot
Jenkins SAML Plugin 2.0.7 and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.
cvelistv5nvd