<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/bitnami_vulndb/10</id>
  <title>Most recent entries from bitnami_vulndb</title>
  <updated>2026-10-02T12:20:35.292744+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-airflow-2023-51702</id>
    <title>BIT-airflow-2023-51702 — Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the…</title>
    <updated>2026-09-08T08:34:36.952000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: airflow</p>
<p>Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any encryption. Additionally, if used with an Airflow version between 2.3.0 and 2.6.0, the configuration dictionary will be logged as plain text in the triggerer service without masking. This allows anyone with access to the metadata or triggerer log to obtain the configuration file and use it to access the Kubernetes cluster.</p>
<p>This behavior was changed in version 7.0.0, which stopped serializing the file contents and started providing the file path instead to read the contents into the trigger. Users are recommended to upgrade to version 7.0.0, which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-airflow-2023-51702"/>
    <published>2024-03-06T10:50:28.804000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-apache-2023-45802</id>
    <title>BIT-apache-2023-45802 — Apache HTTP Server: HTTP/2 stream memory not reclaimed right away on RST</title>
    <updated>2026-09-08T08:34:36.952000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: apache</p>
<p>When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could send new requests and resets, keeping the connection busy and open and causing the memory footprint to keep on growing. On connection close, all resources were reclaimed, but the process might run out of memory before that.</p>
<p>This was found by the reporter during testing of CVE-2023-44487 (HTTP/2 Rapid Reset Exploit) with their own test client. During "normal" HTTP/2 use, the probability to hit this bug is very low. The kept memory would not become noticeable before the connection closes or times out.</p>
<p>Users are recommended to upgrade to version 2.4.58, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-apache-2023-45802"/>
    <published>2024-03-06T10:50:33.560000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-apr-2022-28331</id>
    <title>BIT-apr-2022-28331 — Apache Portable Runtime (APR):  Windows out-of-bounds write in apr_socket_sendv function</title>
    <updated>2026-09-08T08:34:36.952000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: apr</p>
<p>On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-apr-2022-28331"/>
    <published>2024-03-06T10:50:33.685000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-appsmith-2022-4096</id>
    <title>BIT-appsmith-2022-4096 — Server-Side Request Forgery (SSRF) in appsmithorg/appsmith</title>
    <updated>2026-09-10T15:46:03.895000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: appsmith</p>
<p>Server-Side Request Forgery (SSRF) in GitHub repository appsmithorg/appsmith prior to 1.8.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-appsmith-2022-4096"/>
    <published>2024-03-06T10:50:34.576000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-apisix-2023-44487</id>
    <title>BIT-apisix-2023-44487</title>
    <updated>2026-09-08T08:34:36.952000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: apisix</p>
<p>The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-apisix-2023-44487"/>
    <published>2024-03-06T10:50:34.863000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-airflow-2023-50944</id>
    <title>BIT-airflow-2023-50944 — Apache Airflow: Bypass permission verification to read code of other dags</title>
    <updated>2026-09-08T08:34:36.952000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: airflow</p>
<p>Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don't have access. This vulnerability is considered low since it requires an authenticated user to exploit it. Users are recommended to upgrade to version 2.8.1, which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-airflow-2023-50944"/>
    <published>2024-03-06T10:50:38.379000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-apache-2023-43622</id>
    <title>BIT-apache-2023-43622 — Apache HTTP Server: DoS in HTTP/2 with initial windows size 0</title>
    <updated>2026-09-08T08:34:36.952000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: apache</p>
<p>An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known "slow loris" attack pattern.
This has been fixed in version 2.4.58, so that such connection are terminated properly after the configured connection timeout.</p>
<p>This issue affects Apache HTTP Server: from 2.4.55 through 2.4.57.</p>
<p>Users are recommended to upgrade to version 2.4.58, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-apache-2023-43622"/>
    <published>2024-03-06T10:50:43.363000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-apisix-2022-29266</id>
    <title>BIT-apisix-2022-29266 — apisix/jwt-auth may leak secrets in error response</title>
    <updated>2026-09-08T08:34:36.952000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: apisix</p>
<p>In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-apisix-2022-29266"/>
    <published>2024-03-06T10:50:44.063000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-brotli-2020-8927</id>
    <title>BIT-brotli-2020-8927 — Buffer overflow in Brotli library</title>
    <updated>2026-09-10T15:46:03.895000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: brotli</p>
<p>A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-brotli-2020-8927"/>
    <published>2024-03-06T10:50:45.386000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-cassandra-2023-30601</id>
    <title>BIT-cassandra-2023-30601 — Apache Cassandra: Privilege escalation when enabling FQL/Audit logs</title>
    <updated>2026-09-08T08:34:36.952000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: cassandra</p>
<p>Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra
This issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1.</p>
<p>WORKAROUND
The vulnerability requires nodetool/JMX access to be exploitable, disable access for any non-trusted users.</p>
<p>MITIGATION
Upgrade to 4.0.10 or 4.1.2 and leave the new FQL/Auditlog configuration property allow_nodetool_archive_command as false.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-cassandra-2023-30601"/>
    <published>2024-03-06T10:50:45.472000+00:00</published>
  </entry>
</feed>
