PT-2025-44280 · Jenkins · Jenkins Swamp Plugin+1
Denys Digtiar
·
Published
2025-10-29
·
Updated
2025-12-22
·
CVE-2025-64131
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jenkins SAML Plugin versions 4.583.vc68232f7018a and earlier
Description
The Jenkins SAML Plugin does not implement a replay cache. This allows attackers who can gather information about the SAML authentication process between a user’s web browser and Jenkins to replay those requests, potentially authenticating to Jenkins as that user. The issue involves the re-use of valid authentication tokens to gain access to Jenkins environments.
Recommendations
Update Jenkins SAML Plugin to a version later than 4.583.vc68232f7018a .
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Swamp Plugin