Saml
Jenkins · 3 CVEs
CVE-2025-64131
HIGH
Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obta…
Oct 29, 2025
CVE-2021-21678
HIGH
Jenkins SAML Plugin 2.0.7 and earlier allows attackers to craft URLs that would bypass the CSRF protection of any targe…
Aug 31, 2021
CVE-2018-1000602
MEDIUM
A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows…
Jun 26, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-64131 | Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentica… | HIGH | 0.47% | Oct 29, 2025 |
| CVE-2021-21678 | Jenkins SAML Plugin 2.0.7 and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins. | HIGH | 0.81% | Aug 31, 2021 |
| CVE-2018-1000602 | A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate an… | MEDIUM | 0.85% | Jun 26, 2018 |
Showing 1 to 3 of 3 CVEs