VYPR
High severityNVD Advisory· Published Oct 29, 2025· Updated Nov 4, 2025

CVE-2025-64131

CVE-2025-64131

Description

Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a user's web browser and Jenkins to replay those requests, authenticating to Jenkins as that user.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.plugins:samlMaven
< 4.583.585.v22ccc1139f554.583.585.v22ccc1139f55

Affected products

2

Patches

Vulnerability mechanics

References

5

News mentions

1
CVE-2025-64131 · high · VYPR