<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from bitnami_vulndb</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:32:43 +0000</lastBuildDate>
    <item>
      <title>BIT-airflow-2023-51702 — Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the…</title>
      <link>https://cve.radiocsirt.org/vuln/bit-airflow-2023-51702</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: airflow&lt;/p&gt;
&lt;p&gt;Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any encryption. Additionally, if used with an Airflow version between 2.3.0 and 2.6.0, the configuration dictionary will be logged as plain text in the triggerer service without masking. This allows anyone with access to the metadata or triggerer log to obtain the configuration file and use it to access the Kubernetes cluster.&lt;/p&gt;
&lt;p&gt;This behavior was changed in version 7.0.0, which stopped serializing the file contents and started providing the file path instead to read the contents into the trigger. Users are recommended to upgrade to version 7.0.0, which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: airflow&lt;/p&gt;
&lt;p&gt;Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any encryption. Additionally, if used with an Airflow version between 2.3.0 and 2.6.0, the configuration dictionary will be logged as plain text in the triggerer service without masking. This allows anyone with access to the metadata or triggerer log to obtain the configuration file and use it to access the Kubernetes cluster.&lt;/p&gt;
&lt;p&gt;This behavior was changed in version 7.0.0, which stopped serializing the file contents and started providing the file path instead to read the contents into the trigger. Users are recommended to upgrade to version 7.0.0, which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-airflow-2023-51702</guid>
      <pubDate>Wed, 06 Mar 2024 10:50:28 +0000</pubDate>
    </item>
    <item>
      <title>BIT-apache-2023-45802 — Apache HTTP Server: HTTP/2 stream memory not reclaimed right away on RST</title>
      <link>https://cve.radiocsirt.org/vuln/bit-apache-2023-45802</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request&amp;#39;s memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could send new requests and resets, keeping the connection busy and open and causing the memory footprint to keep on growing. On connection close, all resources were reclaimed, but the process might run out of memory before that.&lt;/p&gt;
&lt;p&gt;This was found by the reporter during testing of CVE-2023-44487 (HTTP/2 Rapid Reset Exploit) with their own test client. During &amp;#34;normal&amp;#34; HTTP/2 use, the probability to hit this bug is very low. The kept memory would not become noticeable before the connection closes or times out.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.58, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request&amp;#39;s memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could send new requests and resets, keeping the connection busy and open and causing the memory footprint to keep on growing. On connection close, all resources were reclaimed, but the process might run out of memory before that.&lt;/p&gt;
&lt;p&gt;This was found by the reporter during testing of CVE-2023-44487 (HTTP/2 Rapid Reset Exploit) with their own test client. During &amp;#34;normal&amp;#34; HTTP/2 use, the probability to hit this bug is very low. The kept memory would not become noticeable before the connection closes or times out.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.58, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-apache-2023-45802</guid>
      <pubDate>Wed, 06 Mar 2024 10:50:33 +0000</pubDate>
    </item>
    <item>
      <title>BIT-apr-2022-28331 — Apache Portable Runtime (APR):  Windows out-of-bounds write in apr_socket_sendv function</title>
      <link>https://cve.radiocsirt.org/vuln/bit-apr-2022-28331</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apr&lt;/p&gt;
&lt;p&gt;On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apr&lt;/p&gt;
&lt;p&gt;On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-apr-2022-28331</guid>
      <pubDate>Wed, 06 Mar 2024 10:50:33 +0000</pubDate>
    </item>
    <item>
      <title>BIT-appsmith-2022-4096 — Server-Side Request Forgery (SSRF) in appsmithorg/appsmith</title>
      <link>https://cve.radiocsirt.org/vuln/bit-appsmith-2022-4096</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: appsmith&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (SSRF) in GitHub repository appsmithorg/appsmith prior to 1.8.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: appsmith&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (SSRF) in GitHub repository appsmithorg/appsmith prior to 1.8.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-appsmith-2022-4096</guid>
      <pubDate>Wed, 06 Mar 2024 10:50:34 +0000</pubDate>
    </item>
    <item>
      <title>BIT-apisix-2023-44487</title>
      <link>https://cve.radiocsirt.org/vuln/bit-apisix-2023-44487</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apisix&lt;/p&gt;
&lt;p&gt;The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apisix&lt;/p&gt;
&lt;p&gt;The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-apisix-2023-44487</guid>
      <pubDate>Wed, 06 Mar 2024 10:50:34 +0000</pubDate>
    </item>
    <item>
      <title>BIT-airflow-2023-50944 — Apache Airflow: Bypass permission verification to read code of other dags</title>
      <link>https://cve.radiocsirt.org/vuln/bit-airflow-2023-50944</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: airflow&lt;/p&gt;
&lt;p&gt;Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don&amp;#39;t have access. This vulnerability is considered low since it requires an authenticated user to exploit it. Users are recommended to upgrade to version 2.8.1, which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: airflow&lt;/p&gt;
&lt;p&gt;Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don&amp;#39;t have access. This vulnerability is considered low since it requires an authenticated user to exploit it. Users are recommended to upgrade to version 2.8.1, which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-airflow-2023-50944</guid>
      <pubDate>Wed, 06 Mar 2024 10:50:38 +0000</pubDate>
    </item>
    <item>
      <title>BIT-apache-2023-43622 — Apache HTTP Server: DoS in HTTP/2 with initial windows size 0</title>
      <link>https://cve.radiocsirt.org/vuln/bit-apache-2023-43622</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known &amp;#34;slow loris&amp;#34; attack pattern.
This has been fixed in version 2.4.58, so that such connection are terminated properly after the configured connection timeout.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from 2.4.55 through 2.4.57.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.58, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apache&lt;/p&gt;
&lt;p&gt;An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known &amp;#34;slow loris&amp;#34; attack pattern.
This has been fixed in version 2.4.58, so that such connection are terminated properly after the configured connection timeout.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server: from 2.4.55 through 2.4.57.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 2.4.58, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-apache-2023-43622</guid>
      <pubDate>Wed, 06 Mar 2024 10:50:43 +0000</pubDate>
    </item>
    <item>
      <title>BIT-apisix-2022-29266 — apisix/jwt-auth may leak secrets in error response</title>
      <link>https://cve.radiocsirt.org/vuln/bit-apisix-2022-29266</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apisix&lt;/p&gt;
&lt;p&gt;In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user&amp;#39;s secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: apisix&lt;/p&gt;
&lt;p&gt;In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user&amp;#39;s secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-apisix-2022-29266</guid>
      <pubDate>Wed, 06 Mar 2024 10:50:44 +0000</pubDate>
    </item>
    <item>
      <title>BIT-brotli-2020-8927 — Buffer overflow in Brotli library</title>
      <link>https://cve.radiocsirt.org/vuln/bit-brotli-2020-8927</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: brotli&lt;/p&gt;
&lt;p&gt;A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a &amp;#34;one-shot&amp;#34; decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the &amp;#34;streaming&amp;#34; API as opposed to the &amp;#34;one-shot&amp;#34; API, and impose chunk size limits.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: brotli&lt;/p&gt;
&lt;p&gt;A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a &amp;#34;one-shot&amp;#34; decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the &amp;#34;streaming&amp;#34; API as opposed to the &amp;#34;one-shot&amp;#34; API, and impose chunk size limits.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-brotli-2020-8927</guid>
      <pubDate>Wed, 06 Mar 2024 10:50:45 +0000</pubDate>
    </item>
    <item>
      <title>BIT-cassandra-2023-30601 — Apache Cassandra: Privilege escalation when enabling FQL/Audit logs</title>
      <link>https://cve.radiocsirt.org/vuln/bit-cassandra-2023-30601</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: cassandra&lt;/p&gt;
&lt;p&gt;Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra
This issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1.&lt;/p&gt;
&lt;p&gt;WORKAROUND
The vulnerability requires nodetool/JMX access to be exploitable, disable access for any non-trusted users.&lt;/p&gt;
&lt;p&gt;MITIGATION
Upgrade to 4.0.10 or 4.1.2 and leave the new FQL/Auditlog configuration property allow_nodetool_archive_command as false.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: cassandra&lt;/p&gt;
&lt;p&gt;Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra
This issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1.&lt;/p&gt;
&lt;p&gt;WORKAROUND
The vulnerability requires nodetool/JMX access to be exploitable, disable access for any non-trusted users.&lt;/p&gt;
&lt;p&gt;MITIGATION
Upgrade to 4.0.10 or 4.1.2 and leave the new FQL/Auditlog configuration property allow_nodetool_archive_command as false.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-cassandra-2023-30601</guid>
      <pubDate>Wed, 06 Mar 2024 10:50:45 +0000</pubDate>
    </item>
  </channel>
</rss>
