Beveiligingsadvies

CVE-2026-57289

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-24 13:20:09
Laatst bijgewerkt 2026-06-24 14:15:52
Toegewezen door jenkins
CVSS-score 4.8
Status PUBLISHED

Beschrijving

Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to the configured Bitbucket Server endpoint, allowing attackers able to intercept network traffic to capture the token.