Threats Tagged 'bitnami'
View all threats tagged with 'bitnami'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'bitnami'
Click on any threat for detailed analysis and mitigation recommendations
BIT-gitlab-2026-0934: Incorrect Authorization in GitLabCVE-2026-0934 0 GitLab EE versions from 17.9 up to but not including 18.11.6, 19.0 up to 19.0.3, and 19.1 up to 19.1.1 contain an authorization vulnerability. Under certain conditions, authenticated users with custom role permissions could view, create, or delete protected environment configurations even when CI/CD visibility was disabled for the project. This issue has been remediated in the specified fixed versions. Join the discussion | GCVE Database | 06/29/2026, 06:00:39 UTC Added: 06/29/2026, 22:11:00 UTC |
BIT-gitlab-2026-10086: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabCVE-2026-10086 0 A cross-site scripting (XSS) vulnerability exists in GitLab EE versions from 16.4 up to but not including 18.11.6, 19.0 up to but not including 19.0.3, and 19.1 up to but not including 19.1.1. This vulnerability allows an authenticated user with developer-role permissions to execute arbitrary client-side code in another user's session due to improper sanitization of user-supplied input. The issue has been remediated in the specified fixed versions. Join the discussion | GCVE Database | 06/29/2026, 06:00:42 UTC Added: 06/29/2026, 22:11:00 UTC |
BIT-gitlab-2026-10712: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabCVE-2026-10712 0 A cross-site scripting (XSS) vulnerability exists in GitLab CE/EE versions from 18.10 up to but not including 18.11.6, 19.0 up to but not including 19.0.3, and 19.1 up to but not including 19.1.1. This vulnerability allows an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation during web page generation. The issue has been remediated in the specified fixed versions. Join the discussion | GCVE Database | 06/29/2026, 06:00:46 UTC Added: 06/29/2026, 22:11:00 UTC |
BIT-gitlab-2026-11379: Incorrect Authorization in GitLabCVE-2026-11379 0 GitLab Enterprise Edition versions from 13.11 up to but not including 18.11.6, 19.0 up to 19.0.3, and 19.1 up to 19.1.1 contain an incorrect authorization vulnerability in DAST site profile management. This flaw could allow a user with Developer role to exfiltrate DAST site profile secrets under certain conditions. The issue has been remediated in versions 18.11.6, 19.0.3, and 19.1.1. Join the discussion | GCVE Database | 06/29/2026, 06:00:55 UTC Added: 06/29/2026, 22:11:00 UTC |
BIT-gitlab-2026-12053: Insertion of Sensitive Information into Log File in GitLabCVE-2026-12053 0 A vulnerability in GitLab Enterprise Edition versions 19.1.0 up to but not including 19.1.1 allows insertion of sensitive information into log files due to insufficient output filtering in Duo Workflows. This could enable a user to access sensitive data that had already been committed to a project. The issue has been remediated in version 19.1.1. Join the discussion | GCVE Database | 06/29/2026, 06:00:59 UTC Added: 06/29/2026, 22:11:00 UTC |
BIT-gitlab-2026-12635: Reliance on Reverse DNS Resolution for a Security-Critical Action in GitLabCVE-2026-12635 0 GitLab CE/EE versions from 8.3 up to but not including 18.11.6, 19.0 up to 19.0.3, and 19.1 up to 19.1.1 contain a vulnerability where an authenticated maintainer user could make requests to internal network resources via mirror synchronization due to improper URL validation relying on reverse DNS resolution. This issue has been remediated in the specified fixed versions. Join the discussion | GCVE Database | 06/29/2026, 06:01:01 UTC Added: 06/29/2026, 22:11:00 UTC |
BIT-gitlab-2026-1606: Improper Control of Generation of Code ('Code Injection') in GitLabCVE-2026-1606 0 GitLab CE/EE versions from 14.8 up to but not including 18.11.6, 19.0 up to but not including 19.0.3, and 19.1 up to but not including 19.1.1 contain a vulnerability where an authenticated user could conceal content within a Snippet due to improper input validation. This issue has been remediated in the specified fixed versions. The vulnerability is classified as medium severity and no known exploits are reported in the wild. Join the discussion | GCVE Database | 06/29/2026, 06:01:15 UTC Added: 06/29/2026, 22:11:00 UTC |
BIT-gitlab-2026-2238: Missing Authorization in GitLabCVE-2026-2238 0 A vulnerability in GitLab CE/EE versions 17.5 up to but not including 18.11.6, 19.0 up to but not including 19.0.3, and 19.1 up to but not including 19.1.1 could allow an unauthenticated user to view confidential issue references on public projects due to missing authorization checks. This issue has been remediated in the specified fixed versions. The severity is assessed as medium. Join the discussion | GCVE Database | 06/29/2026, 06:01:30 UTC Added: 06/29/2026, 22:11:00 UTC |
BIT-gitlab-2026-3176: Missing Authorization in GitLabCVE-2026-3176 0 A vulnerability in GitLab Enterprise Edition versions 18.6 up to but not including 18.11.6, 19.0 up to but not including 19.0.3, and 19.1 up to but not including 19.1.1 could allow an authenticated user with limited permissions to access project information due to missing authorization checks. This issue has been remediated in the specified fixed versions. The severity of this vulnerability is considered low. Join the discussion | GCVE Database | 06/29/2026, 06:01:47 UTC Added: 06/29/2026, 22:11:00 UTC |
BIT-gitlab-2026-5309: Authorization Bypass Through User-Controlled Key in GitLabCVE-2026-5309 0 A vulnerability in GitLab Enterprise Edition versions 18.6 up to but not including 18.11.6, 19.0 up to but not including 19.0.3, and 19.1 up to but not including 19.1.1 could allow an authenticated user to read or modify another group's virtual registry cleanup policy settings without proper authorization. This issue has been remediated in the specified fixed versions. Join the discussion | GCVE Database | 06/29/2026, 06:02:09 UTC Added: 06/29/2026, 22:11:00 UTC |
Showing 1 to 10 of 16 results