GHSA-j7r7-7qmf-xq87

Suggest an improvement
Source
https://github.com/advisories/GHSA-j7r7-7qmf-xq87
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-j7r7-7qmf-xq87/GHSA-j7r7-7qmf-xq87.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j7r7-7qmf-xq87
Aliases
Published
2025-10-29T15:31:56Z
Modified
2025-11-05T21:08:07Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Jenkins SAML Plugin does not implement a replay cache
Details

Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache.

This allows attackers able to obtain information about the SAML authentication flow between a user’s web browser and Jenkins to replay those requests, authenticating to Jenkins as that user.

SAML Plugin 4.583.585.v22ccc1139f55 implements a replay cache that rejects replayed requests.

Database specific
{
    "cwe_ids":  [
        "CWE-294"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-10-29T22:03:43Z",
    "nvd_published_at":  "2025-10-29T14:15:57Z",
    "severity":  "HIGH"
}
References

Affected packages

Maven / org.jenkins-ci.plugins:saml

Package

Name
org.jenkins-ci.plugins:saml
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/saml

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.583.585.v22ccc1139f55

Affected versions

0.*
0.2
0.3
0.4
0.5
0.6
0.12
0.13
0.14
1.*
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
2.*
2.0.0
2.0.1
2.0.2
2.0.3
2.0.3.1
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1-275.va_5718591a_999
2.291.vd3f2cd6d1c3e
2.295.vb_3b_1ea_96e7d7
2.296.v0016349946db_
2.297.v1a_dff8e51f90
2.298.vc7a_2b_3958628
2.333.vc81e525974a_c
3.*
3.343.vb_63a_6c3df23c
4.*
4.352.vb_722786ea_79d
4.354.vdc8c005cda_34
4.361.v79b_c2d76d2b_b
4.363.v6cc620b_d37a_2
4.364.veddefb_8dc0ea
4.365.v56110e68e1b_8
4.367.v4f342c34459a
4.369.v13507586ef8c
4.372.v89f13e4c9e97
4.385.v4dea_91565e9d
4.403.v423b_3195a_9ec
4.418.vdfa_7489a_b_a_2d
4.429.v9a_781a_61f1da_
4.464.vea_cb_75d7f5e0
4.485.v99810fb_34d77
4.487.v9f1c3328f1c0
4.496.v56a_6423dca_35
4.501.v4313a_01e3a_18
4.511.vef666858a_167
4.514.vfd5088cc4ed7
4.519.v3927f2f0e020
4.525.v4f6a_7209447e
4.544.v264eea_ed3eed
4.568.v78a_9a_db_8dc9b_
4.569.vcff838e19ed1
4.580.v4cb_5b_9ec2cc2
4.582.v79858eef4044
4.583.vc68232f7018a_

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-j7r7-7qmf-xq87/GHSA-j7r7-7qmf-xq87.json"