<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T20:01:01.364016+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2023-5115</id>
    <title>BREW-ansible-CVE-2023-5115 — Ansible symlink attack vulnerability</title>
    <updated>2026-10-08T20:01:01.368553+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: ansible</p>
<p>An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-ansible-cve-2023-5115"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2023-5115</id>
    <title>CVE-2023-5115 — Ansible: malicious role archive can cause ansible-galaxy to overwrite arbitrary files</title>
    <updated>2026-10-08T20:01:01.368610+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Red Hat Ansible Automation Platform 2.3 for RHEL 8, Red Hat Ansible Automation Platform 2.3 for RHEL 9, Red Hat Ansible Automation Platform 2.4 for RHEL 8, Red Hat Ansible Automation Platform 2.4 for RHEL 9, Red Hat Ansible Automation Platform 1.2</p>
<p>An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2023-5115"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jpvw-p8pr-9g2x</id>
    <title>GHSA-jpvw-p8pr-9g2x — Ansible symlink attack vulnerability</title>
    <updated>2026-10-08T20:01:01.368674+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: ansible</p>
<p>An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jpvw-p8pr-9g2x"/>
  </entry>
</feed>
