<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:30:42.453427+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-00282</id>
    <title>bdu:2022-00282</title>
    <updated>2026-10-03T14:30:42.726770+00:00</updated>
    <content>bdu:2022-00282</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-00282"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2020-1733</id>
    <title>BREW-ansible-CVE-2020-1733</title>
    <updated>2026-10-03T14:30:42.726820+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: ansible</p>
<p>A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with "umask 77 &amp;&amp; mkdir -p &lt;dir&gt;"; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating '/proc/&lt;pid&gt;/cmdline'.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-ansible-cve-2020-1733"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-19559</id>
    <title>cnvd-2020-19559</title>
    <updated>2026-10-03T14:30:42.726859+00:00</updated>
    <content>cnvd-2020-19559</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-19559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-35582</id>
    <title>EUVD-2026-35582</title>
    <updated>2026-10-03T14:30:42.726874+00:00</updated>
    <content>EUVD-2026-35582</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-35582"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-1733</id>
    <title>fkie_cve-2020-1733</title>
    <updated>2026-10-03T14:30:42.726891+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with "umask 77 &amp;&amp; mkdir -p &lt;dir&gt;"; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating '/proc/&lt;pid&gt;/cmdline'.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-1733"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g4mq-6fp5-qwcf</id>
    <title>GHSA-g4mq-6fp5-qwcf — Ansible vulnerable to Exposure of Resource to Wrong Sphere and Insecure Temporary File</title>
    <updated>2026-10-03T14:30:42.726939+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: ansible</p>
<p>A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with "umask 77 &amp;&amp; mkdir -p &lt;dir&gt;"; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating '/proc/&lt;pid&gt;/cmdline'.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g4mq-6fp5-qwcf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-1733</id>
    <title>gsd-2020-1733</title>
    <updated>2026-10-03T14:30:42.726990+00:00</updated>
    <content>gsd-2020-1733</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-1733"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0081-1</id>
    <title>openSUSE-SU-2022:0081-1 — Security update for ansible</title>
    <updated>2026-10-03T14:30:42.727010+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ansible</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:0081-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2020-5</id>
    <title>PYSEC-2020-5</title>
    <updated>2026-10-03T14:30:42.727063+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: ansible</p>
<p>A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with "umask 77 &amp;&amp; mkdir -p &lt;dir&gt;"; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating '/proc/&lt;pid&gt;/cmdline'.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2020-5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:1541</id>
    <title>RHSA-2020:1541 — Red Hat Security Advisory: Ansible security and bug fix update (2.9.7)</title>
    <updated>2026-10-03T14:30:42.727103+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ansible: insecure temporary directory when running become_user from become directive ansible: path injection on dest parameter in fetch module ansible: Extract-Zip function in win_unzip module does not check extracted path ansible: svn module leaks password when specified as a parameter ansible: secrets readable after ansible-vault edit ansible: Information disclosure issue in ldap_attr and ldap_entry modules Ansible: kubectl connection plugin leaks sensitive information Ansible: code injection when using ansible_facts as a subkey Ansible: modules which use files encrypted with vault are not properly cleaned up Ansible: archive traversal vulnerability in ansible-galaxy collection install</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:1541"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-1733</id>
    <title>UBUNTU-CVE-2020-1733</title>
    <updated>2026-10-03T14:30:42.727170+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: ansible, Ubuntu:Pro:18.04:LTS: ansible, Ubuntu:Pro:20.04:LTS: ansible</p>
<p>A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with "umask 77 &amp;&amp; mkdir -p &lt;dir&gt;"; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating '/proc/&lt;pid&gt;/cmdline'.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-1733"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2479</id>
    <title>WID-SEC-W-2023-2479 — Ansible: Schwachstelle ermöglicht Unsicheres Erzeugen von temporären Dateien</title>
    <updated>2026-10-03T14:30:42.727234+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Ansible ausnutzen, um temporäre Dateien zu erzeugen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2479"/>
  </entry>
</feed>
