Jenkins SAML Plugin 2.0.7 and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.
https://github.com/advisories/GHSA-r5w3-pfq8-3r82
https://www.jenkins.io/security/advisory/2021-08-31/#SECURITY-2469