CVE-2026-57289
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
4.8 / 10
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Vulnerability Description
Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to the configured Bitbucket Server endpoint, allowing attackers able to intercept network traffic to capture the token.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-295
Source
NVD
Vendor
Jenkins Project
Product
Jenkins Bitbucket Push and Pull Request Plugin
Discussion (0)
Add Comment
No comments yet. Be the first!