logo

Last Week in AppSec for 04. November 2025

ID: e10e4c0f-f91a-5a00-95e4-43c69662a1c8

STIX ID: report--e10e4c0f-f91a-5a00-95e4-43c69662a1c8

Feed Name: Checkmarx Zero

Threat Score
65/100

Date Published: 2025-11-04

Date Updated: 2026-04-27

Author: Darren Meyer

...
...

This Checkmarx bulletin calls out two security issues: a SAML replay vulnerability in the Jenkins SAML Plugin that can allow attackers to replay captured assertions and impersonate users, and a regression in Apache Tomcat's RewriteValve that mishandles URL decoding and normalization, enabling path traversal and potentially RCE in certain configurations; the report lists affected versions, detection commands, and recommends upgrading to patched releases and reviewing configurations and permissions as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.