Back to CVE List

CVE-2026-57289

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
4.8 / 10
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Vulnerability Description

Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to the configured Bitbucket Server endpoint, allowing attackers able to intercept network traffic to capture the token.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-295
Source
NVD
Vendor
Jenkins Project
Product
Jenkins Bitbucket Push and Pull Request Plugin

External References

Discussion (0)

Add Comment

No comments yet. Be the first!