{"id":"CVE-2025-64131","title":"Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a user's web browser and Jenkins to replay those requests, a…","summary":"Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a user's web browser and Jenkins to replay those requests, a…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-294"],"vendor":"jenkins","product":"saml","affected":["saml < 4.583.585.v22ccc1139f55"],"patched":["saml 4.583.585.v22ccc1139f55"],"published":"2025-10-29","updated":"2026-10-08","sourceUpdated":"2026-10-08T11:10:00.250","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-64131","references":[{"url":"https://www.jenkins.io/security/advisory/2025-10-29/#SECURITY-3613","label":"jenkinsci-cert@googlegroups.com"},{"url":"http://www.openwall.com/lists/oss-security/2025/10/29/2","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00469,"epssPercentile":0.38595,"ingestedAt":"2026-10-08T11:31:27.673Z","slug":"CVE-2025-64131","body":"## Overview\n\nJenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a user's web browser and Jenkins to replay those requests, authenticating to Jenkins as that user.\n\n## Affected\n\n- `saml < 4.583.585.v22ccc1139f55`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `saml 4.583.585.v22ccc1139f55`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}