CVE-2025-64131: Jenkins SAML Plugin does not implement a replay cache
(updated )
Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache.
This allows attackers able to obtain information about the SAML authentication flow between a user’s web browser and Jenkins to replay those requests, authenticating to Jenkins as that user.
SAML Plugin 4.583.585.v22ccc1139f55 implements a replay cache that rejects replayed requests.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-64131 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →