Jenkins Bitbucket Push and Pull Request Plugin unconditionally disables SSL/TLS certificate validation
GHSA-jwhr-h7pc-3974 · CVE-2026-57289
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for the connections it makes to Bitbucket Server using Bearer token authentication.
Because the Bearer token is transmitted in these requests, this allows attackers able to intercept network traffic to capture the token and impersonate the Jenkins controller to Bitbucket Server.
Bitbucket Push and Pull Request Plugin 3.3.9 validates SSL/TLS certificates and hostnames for the connections it makes to Bitbucket Server using Bearer token authentication, using the trust store configured for the Jenkins controller JVM.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-57289
- WEB https://github.com/jenkinsci/bitbucket-push-and-pull-request-plugin/commit/5a0ae2155692beab48c6a0578a3eff22304a2014
- PACKAGE https://github.com/jenkinsci/bitbucket-push-and-pull-request-plugin
- WEB https://github.com/jenkinsci/bitbucket-push-and-pull-request-plugin/releases/tag/bitbucket-push-and-pull-request-3.3.9
- WEB https://www.jenkins.io/security/advisory/2026-06-24/#SECURITY-3856
Ready to move
Start Securing
Free, no credit card | First findings in minutes