CVE-2025-64131: High severity Jenkins SAML Plugin vulnerability

Published Oct 29, 2025
·
Updated

Jenkins SAML Plugin 4.583.vc68232f7018a and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a user's web browser and Jenkins to replay those requests, authenticating to Jenkins as that user.

Other sources

Jenkins SAML Plugin 4.583.vc68232f7018a and earlier does not implement a replay cache.

This allows attackers able to obtain information about the SAML authentication flow between a user’s web browser and Jenkins to replay those requests, authenticating to Jenkins as that user.

SAML Plugin 4.583.585.v22ccc1139f55 implements a replay cache that rejects replayed requests.

— GitHub

Affected Software

3 affected componentsFixes available
Jenkins SAML Plugin<4.583.vc68232f7018a_
maven/org.jenkins-ci.plugins:saml<4.583.585.v22ccc1139f55
4.583.585.v22ccc1139f55
Jenkins Saml Jenkins<4.583.585.v22ccc1139f55

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/org.jenkins-ci.plugins:saml to a version that resolves this vulnerability.

    Fixed in 4.583.585.v22ccc1139f55

Event History

Oct 29, 2025
CVE Published
via MITRE·01:29 PM
Data Sourced
via MITRE·01:29 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:31 PM
Data Sourced
via GitHub·03:31 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-64131?

CVE-2025-64131 has a medium severity rating due to the potential for unauthorized authentication.

2

How do I fix CVE-2025-64131?

To fix CVE-2025-64131, upgrade to a version of Jenkins SAML Plugin later than 4.583.vc68232f7018a_.

3

Who is affected by CVE-2025-64131?

CVE-2025-64131 affects users of Jenkins SAML Plugin versions 4.583.vc68232f7018a_ and earlier.

4

What type of vulnerability is CVE-2025-64131?

CVE-2025-64131 is a replay attack vulnerability that allows attackers to authenticate as users.

5

What functionality is missing in CVE-2025-64131?

CVE-2025-64131 is missing a replay cache implementation which is critical for SAML authentication security.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203