<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 03:36:35 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-02914</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-02914</link>
      <description>bdu:2020-02914</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-02914</guid>
    </item>
    <item>
      <title>BREW-ansible-CVE-2017-7481</title>
      <link>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2017-7481</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as &amp;#39;unsafe&amp;#39; and is not evaluated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as &amp;#39;unsafe&amp;#39; and is not evaluated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-ansible-cve-2017-7481</guid>
    </item>
    <item>
      <title>cnvd-2017-10573</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2017-10573</link>
      <description>cnvd-2017-10573</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2017-10573</guid>
    </item>
    <item>
      <title>EUVD-2026-74714</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-74714</link>
      <description>EUVD-2026-74714</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-74714</guid>
    </item>
    <item>
      <title>fkie_cve-2017-7481</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-7481</link>
      <description>&lt;p&gt;Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as &amp;#39;unsafe&amp;#39; and is not evaluated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as &amp;#39;unsafe&amp;#39; and is not evaluated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-7481</guid>
    </item>
    <item>
      <title>GHSA-w578-j992-554x — Ansible fails to properly mark lookup-plugin results as unsafe</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w578-j992-554x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;Ansible before versions 2.1.6.0, 2.2.3.0, 2.3.1.0, and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as &amp;#39;unsafe&amp;#39; and is not evaluated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;Ansible before versions 2.1.6.0, 2.2.3.0, 2.3.1.0, and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as &amp;#39;unsafe&amp;#39; and is not evaluated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w578-j992-554x</guid>
    </item>
    <item>
      <title>gsd-2017-7481</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-7481</link>
      <description>gsd-2017-7481</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-7481</guid>
    </item>
    <item>
      <title>openSUSE-SU-2017:2976-1 — Security update for ansible</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2017:2976-1</link>
      <description>&lt;p&gt;Security update for ansible&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ansible&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2017:2976-1</guid>
    </item>
    <item>
      <title>PYSEC-2018-41</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2018-41</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as &amp;#39;unsafe&amp;#39; and is not evaluated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as &amp;#39;unsafe&amp;#39; and is not evaluated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2018-41</guid>
    </item>
    <item>
      <title>RHSA-2017:1244 — Red Hat Security Advisory: ansible and openshift-ansible security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2017:1244</link>
      <description>&lt;p&gt;ansible: Arbitrary code execution on control node (incomplete fix for CVE-2016-9587) ansible: Security issue with lookup return not tainting the jinja2 environment&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ansible: Arbitrary code execution on control node (incomplete fix for CVE-2016-9587) ansible: Security issue with lookup return not tainting the jinja2 environment&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2017:1244</guid>
    </item>
    <item>
      <title>SUSE-SU-2017:3029-1 — Security update for ansible and monasca-installer</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2017:3029-1</link>
      <description>&lt;p&gt;Security update for ansible and monasca-installer&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ansible and monasca-installer&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2017:3029-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2017-7481</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-7481</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: ansible&lt;/p&gt;
&lt;p&gt;Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as &amp;#39;unsafe&amp;#39; and is not evaluated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: ansible&lt;/p&gt;
&lt;p&gt;Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as &amp;#39;unsafe&amp;#39; and is not evaluated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-7481</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1808 — Red Hat OpenShift Container Platform: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode mit den…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1808</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift Container Platform ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift Container Platform ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1808</guid>
    </item>
  </channel>
</rss>
