CVE-2026-57289

Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to the configured Bitbucket Server endpoint, allowing attackers able to intercept network traffic to capture the token.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:bitbucket_push_and_pull_request:*:*:*:*:*:jenkins:*:*

History

No history.

Information

Published : 2026-06-24 14:17

Updated : 2026-06-26 19:59


NVD link : CVE-2026-57289

Mitre link : CVE-2026-57289

CVE.ORG link : CVE-2026-57289


JSON object : View

Products Affected

jenkins

  • bitbucket_push_and_pull_request
CWE
CWE-295

Improper Certificate Validation