Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 24 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Bitbucket Plugin Disables SSL/TLS Validation, Allowing Token Capture | |
| Weaknesses | CWE-310 |
Wed, 24 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 24 Jun 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Bitbucket Plugin Disables SSL/TLS Validation, Allowing Token Capture | |
| Weaknesses | CWE-295 CWE-310 |
Wed, 24 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to the configured Bitbucket Server endpoint, allowing attackers able to intercept network traffic to capture the token. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-06-24T14:15:52.030Z
Reserved: 2026-06-24T08:41:44.358Z
Link: CVE-2026-57289
Updated: 2026-06-24T14:15:43.265Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-24T17:00:13Z