<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 05:21:26 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-03714</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-03714</link>
      <description>bdu:2021-03714</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-03714</guid>
    </item>
    <item>
      <title>BREW-ansible-CVE-2019-14904</title>
      <link>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2019-14904</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the &amp;#39;ps&amp;#39; bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the remote host. Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the &amp;#39;ps&amp;#39; bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the remote host. Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-ansible-cve-2019-14904</guid>
    </item>
    <item>
      <title>cnvd-2019-44537</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-44537</link>
      <description>cnvd-2019-44537</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-44537</guid>
    </item>
    <item>
      <title>EUVD-2026-56705</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-56705</link>
      <description>EUVD-2026-56705</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-56705</guid>
    </item>
    <item>
      <title>fkie_cve-2019-14904</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-14904</link>
      <description>&lt;p&gt;A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the &amp;#39;ps&amp;#39; bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the remote host. Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the &amp;#39;ps&amp;#39; bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the remote host. Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-14904</guid>
    </item>
    <item>
      <title>GHSA-gwr8-5j83-483c — OS Command Injection and Improper Input Validation in ansible</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gwr8-5j83-483c</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the &amp;#39;ps&amp;#39; bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the remote host. Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the &amp;#39;ps&amp;#39; bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the remote host. Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gwr8-5j83-483c</guid>
    </item>
    <item>
      <title>gsd-2019-14904</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-14904</link>
      <description>gsd-2019-14904</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-14904</guid>
    </item>
    <item>
      <title>OESA-2021-1349 — ansible security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1349</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP2: ansible&lt;/p&gt;
&lt;p&gt;Ansible is a radically simple model-driven configuration management, multi-node deployment, and remote task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument &amp;amp;quot;password&amp;amp;quot; of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.(CVE-2020-1739)&#13;
&#13;
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes &amp;amp;quot;ansible-vault edit&amp;amp;quot;, another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing secret in the file. This method will delete the file before recreating it insecurely. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.(CVE-2020-1740)&#13;
&#13;
A flaw was found in Ansible Engine when the module package or service is used and the parameter &amp;amp;apos;use&amp;amp;apos; is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP2: ansible&lt;/p&gt;
&lt;p&gt;Ansible is a radically simple model-driven configuration management, multi-node deployment, and remote task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument &amp;amp;quot;password&amp;amp;quot; of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.(CVE-2020-1739)&#13;
&#13;
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes &amp;amp;quot;ansible-vault edit&amp;amp;quot;, another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing secret in the file. This method will delete the file before recreating it insecurely. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.(CVE-2020-1740)&#13;
&#13;
A flaw was found in Ansible Engine when the module package or service is used and the parameter &amp;amp;apos;use&amp;amp;apos; is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1349</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:0513-1 — Security update for ansible</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0513-1</link>
      <description>&lt;p&gt;Security update for ansible&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ansible&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:0513-1</guid>
    </item>
    <item>
      <title>PYSEC-2020-161</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2020-161</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the &amp;#39;ps&amp;#39; bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the remote host. Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the &amp;#39;ps&amp;#39; bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the remote host. Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2020-161</guid>
    </item>
    <item>
      <title>RHSA-2020:0215 — Red Hat Security Advisory: Ansible security and bug fix update (2.9.4)</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:0215</link>
      <description>&lt;p&gt;Ansible: vulnerability in solaris_zone module via crafted solaris zone Ansible: malicious code could craft filename in nxos_file_copy module&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ansible: vulnerability in solaris_zone module via crafted solaris zone Ansible: malicious code could craft filename in nxos_file_copy module&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:0215</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-14904</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-14904</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ansible, Ubuntu:Pro:18.04:LTS: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the &amp;#39;ps&amp;#39; bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the remote host. Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ansible, Ubuntu:Pro:18.04:LTS: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the &amp;#39;ps&amp;#39; bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the remote host. Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-14904</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2482 — Ansible: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2482</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Ansible ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Ansible ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2482</guid>
    </item>
  </channel>
</rss>
