<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/bitnami_vulndb/10</id>
  <title>Most recent entries from bitnami_vulndb</title>
  <updated>2026-10-02T09:44:55.379325+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-golang-2021-33194</id>
    <title>BIT-golang-2021-33194</title>
    <updated>2024-03-06T11:25:28.861000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: golang</p>
<p>golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment input.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-golang-2021-33194"/>
    <published>2024-03-06T11:05:26.460000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-mariadb-2022-27458</id>
    <title>BIT-mariadb-2022-27458</title>
    <updated>2024-03-06T11:25:28.861000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: mariadb</p>
<p>MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Binary_string::free_buffer() at /sql/sql_string.h.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-mariadb-2022-27458"/>
    <published>2024-03-06T10:58:21.495000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-postgresql-2024-24213</id>
    <title>BIT-postgresql-2024-24213</title>
    <updated>2024-03-06T11:25:28.861000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: postgresql</p>
<p>Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/query. NOTE: the vendor's position is that this is an intended feature; also, it exists in the Supabase dashboard product, not the Supabase PostgreSQL product. Specifically, /pg_meta/default/query is for SQL queries that are entered in an intended UI by an authorized user. Nothing is injected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-postgresql-2024-24213"/>
    <published>2024-03-06T11:02:10.168000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-rabbitmq-2020-5419</id>
    <title>BIT-rabbitmq-2020-5419</title>
    <updated>2024-03-06T11:25:28.861000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: rabbitmq</p>
<p>RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (planting) attack and execute arbitrary code.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-rabbitmq-2020-5419"/>
    <published>2024-03-06T11:04:02.503000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-rabbitmq-2021-22117</id>
    <title>BIT-rabbitmq-2021-22117</title>
    <updated>2024-03-06T11:25:28.861000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: rabbitmq</p>
<p>RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-rabbitmq-2021-22117"/>
    <published>2024-03-06T11:03:44.606000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-kafka-2024-27309</id>
    <title>BIT-kafka-2024-27309</title>
    <updated>2024-05-02T07:52:56.618000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: kafka</p>
<p>While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced.Two preconditions are needed to trigger the bug:1. The administrator decides to remove an ACL2. The resource associated with the removed ACL continues to have two or more other ACLs associated with it after the removal.When those two preconditions are met, Kafka will treat the resource as if it had only one ACL associated with it after the removal, rather than the two or more that would be correct.The incorrect condition is cleared by removing all brokers in ZK mode, or by adding a new ACL to the affected resource. Once the migration is completed, there is no metadata loss (the ACLs all remain).The full impact depends on the ACLs in use. If only ALLOW ACLs were configured during the migration, the impact would be limited to availability impact. if DENY ACLs were configured, the impact could include confidentiality and integrity impact depending on the ACLs configured, as the DENY ACLs might be ignored due to this vulnerability during the migration period.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-kafka-2024-27309"/>
    <published>2024-04-16T07:20:25.284000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-solr-2023-44487</id>
    <title>BIT-solr-2023-44487</title>
    <updated>2024-06-23T19:56:34.118000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: solr</p>
<p>The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-solr-2023-44487"/>
    <published>2024-03-06T11:05:51.759000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-wordpress-2023-28492</id>
    <title>BIT-wordpress-2023-28492</title>
    <updated>2024-07-18T07:56:34.499000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: wordpress</p>
<p>Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Functionality Misuse.This issue affects CP Multi View Event Calendar: from n/a through 1.4.10.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-wordpress-2023-28492"/>
    <published>2024-07-18T07:44:25.068000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-envoy-2024-7207</id>
    <title>BIT-envoy-2024-7207</title>
    <updated>2024-09-26T07:51:02.528000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: envoy</p>
<p>A flaw was found in Envoy. It is possible to modify or manipulate headers from external clients when pass-through routes are used for the ingress gateway. This issue could allow a malicious user to forge what is logged by Envoy as a requested path and cause the Envoy proxy to make requests to internal-only services or arbitrary external systems. This is a regression of the fix for CVE-2023-27487.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-envoy-2024-7207"/>
    <published>2024-09-26T07:10:09.460000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-gitlab-2022-4315</id>
    <title>BIT-gitlab-2022-4315</title>
    <updated>2024-11-27T19:40:48.342000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: gitlab</p>
<p>An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-gitlab-2022-4315"/>
    <published>2024-11-05T07:26:59.363000+00:00</published>
  </entry>
</feed>
