CVE-2025-64131: High severity Jenkins SAML Plugin vulnerability
Jenkins SAML Plugin 4.583.vc68232f7018a and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a user's web browser and Jenkins to replay those requests, authenticating to Jenkins as that user.
Other sources
Jenkins SAML Plugin 4.583.vc68232f7018a and earlier does not implement a replay cache.
This allows attackers able to obtain information about the SAML authentication flow between a user’s web browser and Jenkins to replay those requests, authenticating to Jenkins as that user.
SAML Plugin 4.583.585.v22ccc1139f55 implements a replay cache that rejects replayed requests.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.jenkins-ci.plugins:samlto a version that resolves this vulnerability.Fixed in 4.583.585.v22ccc1139f55
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64131?
CVE-2025-64131 has a medium severity rating due to the potential for unauthorized authentication.
How do I fix CVE-2025-64131?
To fix CVE-2025-64131, upgrade to a version of Jenkins SAML Plugin later than 4.583.vc68232f7018a_.
Who is affected by CVE-2025-64131?
CVE-2025-64131 affects users of Jenkins SAML Plugin versions 4.583.vc68232f7018a_ and earlier.
What type of vulnerability is CVE-2025-64131?
CVE-2025-64131 is a replay attack vulnerability that allows attackers to authenticate as users.
What functionality is missing in CVE-2025-64131?
CVE-2025-64131 is missing a replay cache implementation which is critical for SAML authentication security.