216.73.216.133

CVE-2025-64131

· Published 29/10/2025 14:15 · Modified 29/10/2025 14:15

Labels: CVE-2025-64131 2025-10-29CVE-2025-64131CWE-294[email protected]

Essential information

Published
29/10/2025 14:15
Modified
29/10/2025 14:15
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a user's web browser and Jenkins to replay those requests, authenticating to Jenkins as that user.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
jenkins / jenkins saml plugin cpe:2.3:a:jenkins:jenkins_saml_plugin:4.583.vc68232f7018a:*:*:*:*:*:*:*

References