CVE-2025-64131
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-29

Last updated on: 2025-12-22

Assigner: Jenkins Project

Description
Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a user's web browser and Jenkins to replay those requests, authenticating to Jenkins as that user.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-29
Last Modified
2025-12-22
Generated
2026-06-16
AI Q&A
2025-10-29
EPSS Evaluated
2026-06-14
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
jenkins saml to 4.583.585.v22ccc1139f55 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-294 A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in Jenkins SAML Plugin version 4.583.vc68232f7018a_ and earlier, where the plugin does not implement a replay cache. This allows attackers who can observe the SAML authentication flow between a user's web browser and Jenkins to replay those authentication requests, effectively authenticating to Jenkins as that user without their credentials.

Impact Analysis

An attacker exploiting this vulnerability can impersonate legitimate users by replaying captured SAML authentication requests. This can lead to unauthorized access to Jenkins, potentially allowing the attacker to view, modify, or disrupt sensitive build and deployment processes, compromising confidentiality, integrity, and availability.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-64131. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart