<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T05:26:51.408072+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-00275</id>
    <title>bdu:2022-00275</title>
    <updated>2026-10-04T05:26:51.662329+00:00</updated>
    <content>bdu:2022-00275</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-00275"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2020-10729</id>
    <title>BREW-ansible-CVE-2020-10729</title>
    <updated>2026-10-04T05:26:51.662379+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: ansible</p>
<p>A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since no re-evaluation happens. The highest threat from this vulnerability would be that all passwords are exposed at once for the file. This flaw affects Ansible Engine versions before 2.9.6.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-ansible-cve-2020-10729"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-40762</id>
    <title>cnvd-2021-40762</title>
    <updated>2026-10-04T05:26:51.662414+00:00</updated>
    <content>cnvd-2021-40762</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-40762"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-40040</id>
    <title>EUVD-2026-40040</title>
    <updated>2026-10-04T05:26:51.662428+00:00</updated>
    <content>EUVD-2026-40040</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-40040"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-10729</id>
    <title>fkie_cve-2020-10729</title>
    <updated>2026-10-04T05:26:51.662440+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since no re-evaluation happens. The highest threat from this vulnerability would be that all passwords are exposed at once for the file. This flaw affects Ansible Engine versions before 2.9.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-10729"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r6h7-5pq2-j77h</id>
    <title>GHSA-r6h7-5pq2-j77h — Insufficiently random values in Ansible</title>
    <updated>2026-10-04T05:26:51.662461+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: ansible</p>
<p>A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since no re-evaluation happens. The highest threat from this vulnerability would be that all passwords are exposed at once for the file. This flaw affects Ansible Engine versions before 2.9.6.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r6h7-5pq2-j77h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-10729</id>
    <title>gsd-2020-10729</title>
    <updated>2026-10-04T05:26:51.662482+00:00</updated>
    <content>gsd-2020-10729</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-10729"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1349</id>
    <title>OESA-2021-1349 — ansible security update</title>
    <updated>2026-10-04T05:26:51.662493+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP2: ansible</p>
<p>Ansible is a radically simple model-driven configuration management, multi-node deployment, and remote task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically.

Security Fix(es):

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument &amp;quot;password&amp;quot; of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.(CVE-2020-1739)

A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes &amp;quot;ansible-vault edit&amp;quot;, another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing secret in the file. This method will delete the file before recreating it insecurely. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.(CVE-2020-1740)

A flaw was found in Ansible Engine when the module package or service is used and the parameter &amp;apos;use&amp;apos; is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1349"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0081-1</id>
    <title>openSUSE-SU-2022:0081-1 — Security update for ansible</title>
    <updated>2026-10-04T05:26:51.662538+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ansible</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:0081-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2021-105</id>
    <title>PYSEC-2021-105</title>
    <updated>2026-10-04T05:26:51.662570+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: ansible</p>
<p>A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since no re-evaluation happens. The highest threat from this vulnerability would be that all passwords are exposed at once for the file. This flaw affects Ansible Engine versions before 2.9.6.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2021-105"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2020:0784</id>
    <title>RHBA-2020:0784 — Red Hat Bug Fix Advisory: Ansible 2.9.6 release for Ansible Engine 2.9</title>
    <updated>2026-10-04T05:26:51.662589+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ansible: two random password lookups in same task return same value</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2020:0784"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-10729</id>
    <title>UBUNTU-CVE-2020-10729</title>
    <updated>2026-10-04T05:26:51.662603+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: ansible, Ubuntu:Pro:18.04:LTS: ansible</p>
<p>A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since no re-evaluation happens. The highest threat from this vulnerability would be that all passwords are exposed at once for the file. This flaw affects Ansible Engine versions before 2.9.6.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-10729"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3588</id>
    <title>WID-SEC-W-2024-3588 — Ansible: Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-04T05:26:51.662622+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Ansible ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3588"/>
  </entry>
</feed>
