<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 04:43:10 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-00281</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00281</link>
      <description>bdu:2022-00281</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00281</guid>
    </item>
    <item>
      <title>BREW-ansible-CVE-2020-14365</title>
      <link>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2020-14365</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-ansible-cve-2020-14365</guid>
    </item>
    <item>
      <title>EUVD-2026-42400</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-42400</link>
      <description>EUVD-2026-42400</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-42400</guid>
    </item>
    <item>
      <title>fkie_cve-2020-14365</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-14365</link>
      <description>&lt;p&gt;A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-14365</guid>
    </item>
    <item>
      <title>GHSA-m429-fhmv-c6q2 — Improper Verification of Cryptographic Signature in ansible</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m429-fhmv-c6q2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when `disable_gpg_check` is set to `False`, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when `disable_gpg_check` is set to `False`, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m429-fhmv-c6q2</guid>
    </item>
    <item>
      <title>gsd-2020-14365</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-14365</link>
      <description>gsd-2020-14365</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-14365</guid>
    </item>
    <item>
      <title>PYSEC-2020-209</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2020-209</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2020-209</guid>
    </item>
    <item>
      <title>RHSA-2020:3600 — Red Hat Security Advisory: Ansible security and bug fix update (2.8.15)</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:3600</link>
      <description>&lt;p&gt;ansible: atomic_move primitive sets permissive permissions Ansible: masked keys for uri module are exposed into content and json output Ansible: module_args does not censor properly in --check mode ansible: dnf module install packages with no GPG signature&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ansible: atomic_move primitive sets permissive permissions Ansible: masked keys for uri module are exposed into content and json output Ansible: module_args does not censor properly in --check mode ansible: dnf module install packages with no GPG signature&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:3600</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:1427-1 — Security Beta update for SUSE Manager Client Tools and Salt</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:1427-1</link>
      <description>&lt;p&gt;Security Beta update for SUSE Manager Client Tools and Salt&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security Beta update for SUSE Manager Client Tools and Salt&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:1427-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-14365</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-14365</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ansible, Ubuntu:Pro:16.04:LTS: ansible, Ubuntu:Pro:18.04:LTS: ansible, Ubuntu:Pro:20.04:LTS: ansible, Ubuntu:Pro:22.04:LTS: ansible, Ubuntu:24.04:LTS: ansible, Ubuntu:25.10: ansible, Ubuntu:26.04:LTS: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ansible, Ubuntu:Pro:16.04:LTS: ansible, Ubuntu:Pro:18.04:LTS: ansible, Ubuntu:Pro:20.04:LTS: ansible, Ubuntu:Pro:22.04:LTS: ansible, Ubuntu:24.04:LTS: ansible, Ubuntu:25.10: ansible, Ubuntu:26.04:LTS: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-14365</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2469 — Ansible: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2469</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Ansible und Ansible Tower ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Ansible und Ansible Tower ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2469</guid>
    </item>
  </channel>
</rss>
