<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T05:21:26.254164+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-03714</id>
    <title>bdu:2021-03714</title>
    <updated>2026-10-04T05:21:26.622268+00:00</updated>
    <content>bdu:2021-03714</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-03714"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2019-14904</id>
    <title>BREW-ansible-CVE-2019-14904</title>
    <updated>2026-10-04T05:21:26.622323+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: ansible</p>
<p>A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the remote host. Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-ansible-cve-2019-14904"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2019-44537</id>
    <title>cnvd-2019-44537</title>
    <updated>2026-10-04T05:21:26.622399+00:00</updated>
    <content>cnvd-2019-44537</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2019-44537"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-56705</id>
    <title>EUVD-2026-56705</title>
    <updated>2026-10-04T05:21:26.622414+00:00</updated>
    <content>EUVD-2026-56705</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-56705"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-14904</id>
    <title>fkie_cve-2019-14904</title>
    <updated>2026-10-04T05:21:26.622427+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the remote host. Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-14904"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gwr8-5j83-483c</id>
    <title>GHSA-gwr8-5j83-483c — OS Command Injection and Improper Input Validation in ansible</title>
    <updated>2026-10-04T05:21:26.622452+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: ansible</p>
<p>A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the remote host. Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gwr8-5j83-483c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-14904</id>
    <title>gsd-2019-14904</title>
    <updated>2026-10-04T05:21:26.622481+00:00</updated>
    <content>gsd-2019-14904</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-14904"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1349</id>
    <title>OESA-2021-1349 — ansible security update</title>
    <updated>2026-10-04T05:21:26.622493+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP2: ansible</p>
<p>Ansible is a radically simple model-driven configuration management, multi-node deployment, and remote task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically.

Security Fix(es):

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument &amp;quot;password&amp;quot; of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.(CVE-2020-1739)

A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes &amp;quot;ansible-vault edit&amp;quot;, another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing secret in the file. This method will delete the file before recreating it insecurely. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.(CVE-2020-1740)

A flaw was found in Ansible Engine when the module package or service is used and the parameter &amp;apos;use&amp;apos; is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1349"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0513-1</id>
    <title>openSUSE-SU-2020:0513-1 — Security update for ansible</title>
    <updated>2026-10-04T05:21:26.622540+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ansible</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:0513-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2020-161</id>
    <title>PYSEC-2020-161</title>
    <updated>2026-10-04T05:21:26.622563+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: ansible</p>
<p>A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the remote host. Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2020-161"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:0215</id>
    <title>RHSA-2020:0215 — Red Hat Security Advisory: Ansible security and bug fix update (2.9.4)</title>
    <updated>2026-10-04T05:21:26.622583+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ansible: vulnerability in solaris_zone module via crafted solaris zone Ansible: malicious code could craft filename in nxos_file_copy module</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:0215"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-14904</id>
    <title>UBUNTU-CVE-2019-14904</title>
    <updated>2026-10-04T05:21:26.622601+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: ansible, Ubuntu:Pro:18.04:LTS: ansible</p>
<p>A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the remote host. Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-14904"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2482</id>
    <title>WID-SEC-W-2023-2482 — Ansible: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode</title>
    <updated>2026-10-04T05:21:26.622623+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Ansible ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2482"/>
  </entry>
</feed>
