Security Advisory

CVE-2026-57289

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-24 13:20:09
Last updated 2026-06-24 14:15:52
Assigner jenkins
CVSS score not scored
State PUBLISHED

Description

Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to the configured Bitbucket Server endpoint, allowing attackers able to intercept network traffic to capture the token.