Skip to main content

Threats Tagged 'bitnami'

View all threats tagged with 'bitnami'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: bitnami

Threats Tagged 'bitnami'

Click on any threat for detailed analysis and mitigation recommendations

When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer over cookie. The request then executes -- and is recorded in the audit log -- as the cookie's principal rather than the identity the client explicitly presented. Only Apache Airflow 3.3.0 and 3.3.1 are affected. Earlier releases do not contain the code path that caches the cookie-derived user, and are not vulnerable. Exploiting this requires an attacker to first place a valid session cookie of their own into the victim's browser or client: for example by cookie tossing from a sibling subdomain, through cross-site scripting in a separate application sharing a parent domain, or via a shared workstation. Deployments that host the Airflow UI on a domain shared with other applications are therefore the most exposed; a deployment on a dedicated domain with no co-hosted applications is not reachable this way. The consequence is principal confusion and misattributed audit records rather than a direct privilege escalation. Users of 3.3.0 or 3.3.1 should upgrade to Apache Airflow 3.3.2 or later, which resolves the caller from the explicitly supplied credential whenever one is present.

Join the discussion
0

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a TLS handshake. This can happen in a non-deterministic manner that is beyond the attacker's control. This may cause a heap buffer overflow in the NGINX worker process leading to a restart and/or limited data corruption. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or limited data corruption. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Join the discussion

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * python-sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing (CVE-2026-54284) * python-sqlparse: Denial of Service via inefficient SQL parsing (CVE-2026-59893) * python-sqlparse: Denial of Service via quadratic CPU consumption in comment grouping (CVE-2026-71491) * python3.12-sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing (CVE-2026-54284) * python3.12-sqlparse: Denial of Service via inefficient SQL parsing (CVE-2026-59893) * python3.12-sqlparse: Denial of Service via quadratic CPU consumption in comment grouping (CVE-2026-71491) * receptor: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * receptor: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) * receptor: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * receptor: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * receptor: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * receptor: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. For details about this release, refer to the release notes listed in the References section.

Join the discussion

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the extra ibu container images for Red Hat OpenShift Container Platform 4.22. All OpenShift Container Platform users are advised to upgrade to these updated packages and images.

Join the discussion

Multiple arbitrary code execution vulnerabilities have been identified in PostgreSQL, affecting various functions and plugins including tsvector, tsquery, logical decoding plugin, regexp, pltcl, plperl, fuzzystrmatch, cursor lifecycle, POSIX timezone abbreviation, and pg_dump transform lists. These vulnerabilities are addressed in a security update released by Red Hat for PostgreSQL 15 and related versions. The update is rated as important by Red Hat Product Security and fixes several critical issues that could allow attackers to execute arbitrary code.

Join the discussion

Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout response but revokes nothing, so the token remains valid until it expires. An attacker who already holds a copy of that token keeps the victim's access after the victim has logged out and believes the session ended; the default token lifetime is 24 hours and is configurable. Affects API clients that authenticate with a bearer token rather than the browser session cookie. The attacker must already possess a copy of a valid token; obtaining one is outside the scope of this issue, and no privileges beyond the victim's own are gained. Users of apache-airflow are recommended to upgrade to apache-airflow version 3.3.2 or later, which fixes the issue.

Join the discussion

Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. Any authenticated user holding asset-read access could therefore enumerate asset events — including the source Dag ID, task ID, run ID and event timestamps — for Dags they have no permission to see. Because the filter was also absent from the count query, `total_entries` and pagination disclosed the existence of hidden Dags even without inspecting individual rows. Deployments are affected whenever per-Dag access control is used to separate teams or tenants; no special configuration is required. Upgrade to apache-airflow 3.3.2 or later.

Join the discussion

Red Hat Lightspeed in Satellite analyzes system health and configuration by applying predefined rules to a small set of local data, such as installed packages, running services, and configuration settings.

Join the discussion

This update includes the following RPMs: tomcat11: * tomcat11-11.0.26-0.1.hum1 (noarch) * tomcat11-admin-webapps-11.0.26-0.1.hum1 (noarch) * tomcat11-common-11.0.26-0.1.hum1 (noarch) * tomcat11-docs-webapp-11.0.26-0.1.hum1 (noarch) * tomcat11-el-6.0-api-11.0.26-0.1.hum1 (noarch) * tomcat11-jsp-4.0-api-11.0.26-0.1.hum1 (noarch) * tomcat11-lib-11.0.26-0.1.hum1 (noarch) * tomcat11-servlet-6.1-api-11.0.26-0.1.hum1 (noarch) * tomcat11-user-instance-11.0.26-0.1.hum1 (noarch) * tomcat11-webapps-11.0.26-0.1.hum1 (noarch) * tomcat11-11.0.26-0.1.hum1.src (src)

Join the discussion

This update includes the following RPMs: grafana12.4: * grafana12.4-12.4.10-0.4.hum1 (aarch64, x86_64) * grafana12.4-12.4.10-0.4.hum1.src (src) Security Fix(es): grafana12.4: * CVE-2026-86472

Join the discussion

Showing 1 to 10 of 1264 results

Filters:Tag: bitnami
Page 1 of 127
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses