CVE-2025-64131 affects Jenkins SAML Plugin versions 4.583.vc68232f7018a and earlier, stemming from a missing replay cache implementation. This high-severity vulnerability (CVSS 7.5) allows attackers to replay SAML authentication requests, potentially gaining unauthorized access to Jenkins as an authenticated user, provided they can intercept the authentication flow. While the attack complexity is high due to the requirement of obtaining SAML flow information, the potential impact includes full compromise of confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.583.585.v22ccc1139f55CPE matchmatch criteria | cpe:2.3:a:jenkins:saml:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.