Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'bitnami'

View all threats tagged with 'bitnami'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: bitnami

Threats Tagged 'bitnami'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-51297CVE-2026-51297
0
Join the discussion
BIT-discourse-2026-44787: Discourse: Signup-time primary_group_id assignment grants whisperer accessCVE-2026-44787
0

A vulnerability in Discourse prior to versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5 allows newly registered users during signup to assign themselves a primary_group_id. This improper assignment grants them whisper-group privileges without legitimate membership on sites configured with whispers_allowed_groups. The issue has been fixed in the specified patched versions.

Join the discussion
BIT-discourse-2026-45780: Discourse: Private event sample invitees are serialized to non-invited event viewersCVE-2026-45780
0

Discourse versions prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5 have a vulnerability where private event invitee information is exposed to unauthorized users. Specifically, the EventSerializer component could leak invited group names, sample invitees, and attendance statistics to users who can view the topic but should not see the private event invitee list. This issue has been fixed in the stated versions.

Join the discussion
BIT-discourse-2026-45788: Discourse: Secure uploads exposed by hotlinked image copyingCVE-2026-45788
0

Discourse versions prior to 2026.1.5, 2026.4.2, and 2026.5.1 have a vulnerability where secure uploads could be exposed via the pull_hotlinked_images feature if an attacker knew the secured upload URL and the secure_uploads setting was enabled. This issue allows unauthorized access to uploads intended to be secure. The vulnerability is fixed in versions 2026.1.5, 2026.4.2, and 2026.5.1 and later.

Join the discussion
BIT-discourse-2026-46413: Discourse: Regular users can route multipart uploads into the admin backup storeCVE-2026-46413
0

Discourse versions prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5 contain a vulnerability where regular users could route direct S3 multipart uploads through the ExternalUploadManager into the admin backup store. This issue has been fixed in the specified versions. The vulnerability is classified as medium severity.

Join the discussion
BIT-discourse-2026-49256: Discourse: Hidden tag names leaked via category serializersCVE-2026-49256
0

Discourse versions prior to 2026.1.5, 2026.4.2, and 2026.5.1 could leak restricted tag and tag-group names via category and group endpoints to unauthorized and anonymous users. This information disclosure affects tags attached to publicly readable categories. The issue is fixed in versions 2026.1.5, 2026.4.2, and 2026.5.1 and later.

Join the discussion
BIT-discourse-2026-53961: Discourse: Forged AWS SNS bounce notifications can disable a targeted user's email (missing TopicArn binding)CVE-2026-53961
0

Discourse versions prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5 contain a vulnerability in the AWS SES bounce webhook. The webhook verified that SNS messages were signed by Amazon but failed to restrict them to trusted TopicArn values. This allowed any AWS account holder to send validly signed forged bounce notifications, which could disable a targeted user's email. The issue is fixed in the specified patched versions.

Join the discussion
BIT-discourse-2026-53962: Discourse: Insufficient SVG sanitization logicCVE-2026-53962
0

Discourse versions prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5 contain insufficient SVG sanitization in upload and user avatar handling. This vulnerability could allow cross-site scripting (XSS) when users visit certain uncommon URLs. The issue has been fixed in the specified later versions.

Join the discussion
BIT-discourse-2026-53963: Discourse: Stored-XSS in 2FA delete confirmation modalCVE-2026-53963
0

Discourse versions prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5 contain a stored cross-site scripting (XSS) vulnerability in the two-factor authentication (2FA) delete confirmation modal. The vulnerability arises because a malicious second factor name on an attacker-controlled account is not properly escaped in the confirmation dialog. This flaw can be triggered when an administrator impersonates the affected account. The issue is fixed in the specified patched versions.

Join the discussion
BIT-discourse-2026-55424: Discourse: Topic featured link susceptible to stored XSSCVE-2026-55424
0

Discourse versions prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5 contain a stored cross-site scripting (XSS) vulnerability in the topic featured link feature. The vulnerability arises because the featured link was not properly normalized and escaped before rendering in the topic list. This allows a user with permission to set a featured link to inject JavaScript code if the default Content Security Policy protections are modified or disabled. The issue has been fixed in the specified versions.

Join the discussion

Showing 1 to 10 of 15 results

Filters:Tag: bitnami
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses