CVE-2026-57289Medium· 4.8▾ SunlitJenkins Bitbucket Push and Pull Request Plugin unconditionally disables SSL/TLS certificate validation
▾ Sunlit zone — Low / medium · no exploitation signal
impact 26.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.2%
Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for the connections it makes to Bitbucket Server using Bearer token authentication.
Because the Bearer token is transmitted in these requests, this allows attackers able to intercept network traffic to capture the token and impersonate the Jenkins controller to Bitbucket Server.
Bitbucket Push and Pull Request Plugin 3.3.9 validates SSL/TLS certificates and hostnames for the connections it makes to Bitbucket Server using Bearer token authentication, using the trust store configured for the Jenkins controller JVM.
io.jenkins.plugins:bitbucket-push-and-pull-request < 3.3.9Upgrade to a patched release:
io.jenkins.plugins:bitbucket-push-and-pull-request 3.3.9Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57300Medium· 4.3Jenkins MCP Server Plugin missing a permission check
CVE-2026-57306Medium· 4.2Jenkins Zowe zDevOps Plugin has a CSRF vulnerability
CVE-2026-57307Medium· 4.2Jenkins Zowe zDevOps Plugin has a missing permission check
CVE-2026-57284Medium· 4.3Jenkins Pipeline: Groovy Plugin vulnerable to unrestricted instantiation of types
CVE-2026-57283Medium· 4.3Jenkins Pipeline: Groovy Plugin has a CSRF vulnerability
CVE-2021-20327Medium· 6.4A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate