Vulnerabilities
Vulnerable Software
Jenkins:  >> Saml  Security Vulnerabilities
Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a user's web browser and Jenkins to replay those requests, authenticating to Jenkins as that user.
CVSS Score
7.5
EPSS Score
0.0
Published
2025-10-29
Jenkins SAML Plugin 2.0.7 and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.
CVSS Score
8.8
EPSS Score
0.001
Published
2021-08-31
A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate another users if they can control the pre-authentication session.
CVSS Score
5.9
EPSS Score
0.0
Published
2018-06-26


Contact Us

Shodan ® - All rights reserved