Vulnerability GHSA-jwhr-h7pc-3974

Medium Risk
MEDIUM RISK
CVSS Score: 4.8
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 months ago
June 24, 2026 at 03:31 PM UTC
Jenkins Bitbucket Push and Pull Request Plugin unconditionally disables SSL/TLS certificate validation
1.1.0 - 1.2.0 and 1.4.0 - 2.2.1 and 2.4.0 and 3.2.0
1.1.0 - 1.2.0 and 1.4.0 - 2.2.1 and 2.4.0 and 3.2.0

Summary

Jenkins Bitbucket Push and Pull Request Plugin unconditionally disables SSL/TLS certificate validation

Details

Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for the connections it makes to Bitbucket Server using Bearer token authentication.

Because the Bearer token is transmitted in these requests, this allows attackers able to intercept network traffic to capture the token and impersonate the Jenkins controller to Bitbucket Server.

Bitbucket Push and Pull Request Plugin 3.3.9 validates SSL/TLS certificates and hostnames for the connections it makes to Bitbucket Server using Bearer token authentication, using the trust store configured for the Jenkins controller JVM.

Timeline

Published
3 months ago
June 24, 2026 at 03:31 PM UTC
Last Modified
2 days ago
September 25, 2026 at 07:15 PM UTC