CVE-2026-57289: Medium severity Jenkins Bitbucket Push and Pull Request Plugin vulnerability
Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to the configured Bitbucket Server endpoint, allowing attackers able to intercept network traffic to capture the token.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jenkins Bitbucket Push and Pull Request Pluginto a version that resolves this vulnerability.Fixed in 3.3.8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57289?
CVE-2026-57289 has a risk score of 55, indicating a moderate severity level.
How do I fix CVE-2026-57289?
To address CVE-2026-57289, update the Jenkins Bitbucket Push and Pull Request Plugin to version 3.3.9 or later.
What vulnerabilities does CVE-2026-57289 introduce?
CVE-2026-57289 introduces the risk of unencrypted Bearer token authentication, exposing connections to potential interception.
Which software is affected by CVE-2026-57289?
CVE-2026-57289 affects Jenkins Bitbucket Push and Pull Request Plugin version 3.3.8 and earlier.
In what scenarios does CVE-2026-57289 pose a threat?
CVE-2026-57289 poses a threat when network traffic can be intercepted, enabling attackers to capture Bearer tokens.