Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j7r7-7qmf-xq87 | Jenkins SAML Plugin does not implement a replay cache |
Mon, 22 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins saml
|
|
| CPEs | cpe:2.3:a:jenkins:saml:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins saml
|
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 30 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins jenkins |
|
| Vendors & Products |
Jenkins
Jenkins jenkins |
Wed, 29 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-294 | |
| Metrics |
cvssV3_1
|
Wed, 29 Oct 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a user's web browser and Jenkins to replay those requests, authenticating to Jenkins as that user. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-11-04T21:14:22.397Z
Reserved: 2025-10-28T07:34:37.541Z
Link: CVE-2025-64131
Updated: 2025-11-04T21:14:22.397Z
Status : Analyzed
Published: 2025-10-29T14:15:57.133
Modified: 2025-12-22T15:26:58.437
Link: CVE-2025-64131
No data.
OpenCVE Enrichment
Updated: 2025-10-30T14:38:25Z
Github GHSA