High severityNVD Advisory· Published Oct 29, 2025· Updated Nov 4, 2025
CVE-2025-64131
CVE-2025-64131
Description
Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a user's web browser and Jenkins to replay those requests, authenticating to Jenkins as that user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:samlMaven | < 4.583.585.v22ccc1139f55 | 4.583.585.v22ccc1139f55 |
Affected products
2- Range: 0
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-j7r7-7qmf-xq87ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-64131ghsaADVISORY
- www.jenkins.io/security/advisory/2025-10-29/ghsavendor-advisoryWEB
- www.openwall.com/lists/oss-security/2025/10/29/2ghsaWEB
- github.com/jenkinsci/saml-plugin/commit/6170b1013daf52770de29a66aeb57893aae1d7d6ghsaWEB
News mentions
1- Jenkins Security Advisory 2025-10-29Jenkins Security Advisories · Oct 29, 2025