Replay Cache Vulnerability in Jenkins SAML Plugin
CVE-2025-64131

7.5HIGH

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
29 October 2025

What is CVE-2025-64131?

The Jenkins SAML Plugin, specifically version 4.583.vc68232f7018a_ and earlier, is susceptible to a replay cache vulnerability. This flaw allows malicious actors to intercept and replay SAML authentication requests. By exploiting this vulnerability, attackers can authenticate to Jenkins as legitimate users, gaining unauthorized access to sensitive information and potentially compromising the integrity of the system. It is crucial for users of affected versions to implement necessary updates and security measures to mitigate this risk.

Affected Version(s)

Jenkins SAML Plugin 0 <= 4.583.vc68232f7018a_

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64131 : Replay Cache Vulnerability in Jenkins SAML Plugin