CVE-2026-57289

Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to the configured Bitbucket Server endpoint, allowing attackers able to intercept network traffic to capture the token.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:bitbucket_push_and_pull_request:*:*:*:*:*:jenkins:*:*

History

26 Jun 2026, 19:59

Type Values Removed Values Added
References () https://www.jenkins.io/security/advisory/2026-06-24/#SECURITY-3856 - () https://www.jenkins.io/security/advisory/2026-06-24/#SECURITY-3856 - Vendor Advisory
CPE cpe:2.3:a:jenkins:bitbucket_push_and_pull_request:*:*:*:*:*:jenkins:*:*
First Time Jenkins
Jenkins bitbucket Push And Pull Request

24 Jun 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
CWE CWE-295

24 Jun 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-24 14:17

Updated : 2026-06-26 19:59


NVD link : CVE-2026-57289

Mitre link : CVE-2026-57289

CVE.ORG link : CVE-2026-57289


JSON object : View

Products Affected

jenkins

  • bitbucket_push_and_pull_request
CWE
CWE-295

Improper Certificate Validation